Invention Grant
- Patent Title: Prioritizing security risks for a computer system based on historical events collected from the computer system environment
-
Application No.: US15836796Application Date: 2017-12-08
-
Publication No.: US10691796B1Publication Date: 2020-06-23
- Inventor: Ryan G. Stolte , Firas S. Rifai , Humphrey Christian , Joseph Anthony DeRobertis , Shmuel Yehonatan Green
- Applicant: CA, INC.
- Applicant Address: US CA San Jose
- Assignee: CA, Inc.
- Current Assignee: CA, Inc.
- Current Assignee Address: US CA San Jose
- Agency: FisherBroyles, LLP
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06F21/55

Abstract:
A method of identifying security risks in a computer system that includes several computers executing different applications is provided. The method receives event data about threat events associated with a set of applications executing on a set of computers in the computer system. The method, for each event, compares a set of parameters associated with the event with a set of historical parameters maintained for a similar event. The method, based on the comparisons, defines a normality characterization for each event to express a probability of an exploit of the application associated with the event. The method, based on the normality characterization, defines a prioritized display of security risks due to the threat events associated with the set of application.
Information query