Invention Grant
- Patent Title: System, method and computer readable medium for identifying missing organizational security detection system rules
-
Application No.: US17182278Application Date: 2021-02-23
-
Publication No.: US11651072B2Publication Date: 2023-05-16
- Inventor: Eran Alshech , Adam Amram
- Applicant: CYBERPROOF ISRAEL LTD.
- Applicant Address: IL Tel Aviv
- Assignee: CyberProof Israel Ltd.
- Current Assignee: CyberProof Israel Ltd.
- Current Assignee Address: IL Tel Aviv
- Main IPC: G06F21/55
- IPC: G06F21/55 ; G06N3/04 ; H04L9/40 ; G06F18/22

Abstract:
A system for identifying missing organizational security detection system rules, the system includes at least one processing circuitry configured to provide a known cyber-attack techniques repository including information of known cyber-attack techniques and required SIEM (or any other organizational security detection system such as EDR, firewall, etc.) rules required for protecting against each of the known cyber-attack techniques, the known rules being in a generic SIEM rules format; obtain existing SIEM rules of a SIEM of an organization, the existing SIEM rules being in a vendor-specific language, other than the generic SIEM rules format; translate the existing SIEM rules to the generic SIEM rules format, using a translation system, giving rise to translated SIEM rules; compare the translated SIEM rules to the required SIEM rules to identify missing rules, being the required SIEM rules not included in the translated SIEM rules.
Public/Granted literature
Information query