Invention Grant
- Patent Title: Genetic fuzzing for customization of security operations center rules per organization
-
Application No.: US16801173Application Date: 2020-02-26
-
Publication No.: US11720802B2Publication Date: 2023-08-08
- Inventor: Fady Copty , Benjamin Zeltser
- Applicant: International Business Machines Corporation
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agent Gregory J Kirsch
- Main IPC: G06N3/126
- IPC: G06N3/126 ; G06F21/57 ; G06N5/02

Abstract:
Embodiments may provide techniques that that may automatically generate a customized SOC rule set for an organization. For example, in an embodiment, a method may be implemented in a computer comprising a processor, memory accessible by the processor, and computer program instructions stored in the memory and executable by the processor, the method may comprise simulating operation of a security incident and event management system by running a plurality of rules of the system on labeled data, determining fitness metrics of the plurality of rules, selecting at least one rule of the plurality of rules based on the determined fitness metrics; modifying the selected rule to form an updated rule, and repeating running the updated rule on the labeled data, determining fitness metrics of the updated rule, and mutating the updated rule.
Public/Granted literature
- US20210264286A1 GENETIC FUZZING FOR CUSTOMIZATION OF SECURITY OPERATIONS CENTER RULES PER ORGANIZATION Public/Granted day:2021-08-26
Information query