Invention Grant
- Patent Title: Adaptive rule generation for security event correlation
-
Application No.: US16387632Application Date: 2019-04-18
-
Publication No.: US11431734B2Publication Date: 2022-08-30
- Inventor: Matthias Seul , Arjun Udupi Raghavendra , Tim Uwe Scheideler , Tiziano Airoldi
- Applicant: KYNDRYL, INC.
- Applicant Address: US NY New York
- Assignee: KYNDRYL, INC.
- Current Assignee: KYNDRYL, INC.
- Current Assignee Address: US NY New York
- Agency: Roberts Calderon Safran & Cole, P.C.
- Agent Ken Han; Andrew M. Calderon
- Main IPC: H04L9/00
- IPC: H04L9/00 ; H04L9/40 ; G06F17/15

Abstract:
A computer-implemented method for dynamically identifying security threats comprising a cyber-attack chain composed of a sequence of partial cyber-attacks represented by attack patterns may be provided. The method comprises receiving a sequence of security events, determining, a first cyber-attack pattern by applying a set of predefined rules for detecting an indicator of compromise of a first partial cyber-attack of the cyber-attack chain—thereby, identifying a specific cyber-attack chain—and determining a type and an attribute in the pattern of the first partial cyber-attack. The method comprises further configuring at least one rule for a downstream partial cyber-attack in the specific cyber-attack chain based on the type and the attribute in the attack pattern of the first partial cyber-attack, and adding the at least one configured rule to the set of predefined rules to be used by the correlation engine for dynamically identifying security threats to information technology systems.
Public/Granted literature
- US20200336497A1 DETECTING SENSITIVE DATA EXPOSURE VIA LOGGING Public/Granted day:2020-10-22
Information query