Collaborative infrastructure supporting cyber-security analytics in industrial networks
Abstract:
A system comprising a computer-readable storage medium storing at least one program, and a method for reducing cyber-security related false positive alerts is presented. In example embodiments the method may include identifying an abnormal operation pattern in the network system that may signal a cyber-security threat. In response to identifying the abnormal operation pattern, data related to a state change of an asset included in the network system is accessed. The method may further include determining that the abnormal operation pattern and the state change of the asset are correlated, and based on this determination, determining that the abnormal operation pattern is a false positive indicator with respect to the cyber-security threat.
Information query
Patent Agency Ranking
0/0