Automated threat response in extended detection and response (XDR) systems
Techniques and architecture are described for automated threat response and remediation of incidents generated by single or multiple security products. The techniques and architecture provide a framework for automated threat response and remediation of incidents generated by single or multiple security products, especially for extended detection and response (XDR) systems. In particular, the techniques and architecture provide for an automated threat response that is handled by an auto-analyst engine emulating security analysts' steps during incident response and remediation. The automated threat response automatically confirms or disapproves of detection verdicts thereby reducing false positives that analysts usually have to deal with. If any actions are needed from a security analyst, a concise report of actions taken, gathered information and recommended next steps are provided by the automated threat response, significantly reducing the time and resources needed to resolve an incident.
1 . A method comprising:
ingesting, at an automated threat response within a network, network alert events from multiple telemetry sources, wherein the multiple telemetry sources comprise (i) multiple security products from multiple vendors, (ii) multiple security product vendors, and (iii) operating system logs;
based on the ingesting, automatically determining, by an auto-analyst engine of the automated threat response, whether a particular network alert event is a security problem; and
based at least in part on the automatically determining whether the particular network alert event is a security problem, taking, by the auto-analyst engine, at least one further first step relating to the particular network alert event,
wherein if the particular network alert event is not a security problem, the at least one further first step comprises:
generating, by the auto-analyst engine, a summary relating to the particular network alert event, wherein the summary comprises an indication of the particular network alert event as a false positive; and
adding the summary to an incident database, and
wherein if the particular network alert event is a security problem, the at least one further first step comprises:
adding, by the auto-analyst engine, information regarding the particular network alert event to the incident database.
2 . The method of claim 1 , further comprising:
automatically determining, by the auto-analyst engine, whether a process is monitored; and
based at least in part on the automatically determining whether the process is monitored, taking, by the auto-analyst engine, at least one further second step relating to the particular network alert event:
wherein if the process is not monitored, the at least one further second step comprises at least one of (i) generating the summary, by the auto-analyst engine, relating to the particular network alert event, wherein the summary comprises the indication of the particular network alert event as a true positive, (ii) adding the summary to the incident database, or (iii) taking a remediation action.
3 . The method of claim 2 , wherein if the particular network alert event is a security problem, the method further comprises:
determining, by the auto-analyst engine, the process that initiated a connection to the network device, wherein the connection is related to the particular network alert event.
4 . The method of claim 3 , wherein if the process is monitored, the at least one further second step comprises:
determining, by the auto-analyst engine, whether the process is still running,
wherein if the process is not still running, the at least one further second step comprises at least one of (i) generating the summary, by the auto-analyst engine, relating to the particular network alert event, wherein the summary comprises the indication of the particular network alert event as a true positive, (ii) adding the summary to the incident database, or (ii) taking the remediation action.
5 . The method of claim 4 , wherein if the process is still running, the method further comprises:
at least one of closing, by the auto-analyst engine, the connection to a uniform resource locator (URL), closing, by the auto-analyst engine, a port on which communication is occurring, isolating, by the auto-analyst engine, the network device, discontinuing, by the auto-analyst engine, the process running, or quarantining, by the auto-analyst engine, the network device; and
generating, by the auto-analyst engine, the summary relating to the particular network alert event, wherein the summary comprises the indication of the particular network alert event as a true positive, (ii) adding the summary to the incident database.
6 . The method of claim 1 , further comprising:
obtaining, by the auto-analyst engine, information related to the particular network alert event from at least one of (i) one or more security product application programming interfaces (APIs) or (ii) the incident database.
7 . The method of claim 1 , further comprising:
suggesting, by the auto-analyst engine to a network security entity, further actions that may be taken based at least in part on a history of network alert events.
8 . The method of claim 1 , further comprising:
providing, by the auto-analyst engine to a network security entity, the summary; and
receiving, by the auto-analyst engine from the network security entity, feedback related to the summary.
9 . A system comprising:
one or more processors; and
one or more non-transitory computer-readable media storing computer-executable instructions that, when executed by the one or more processors, cause the one or more processors to perform actions comprising:
ingesting, at an automated threat response within a network, network alert events from multiple telemetry sources, wherein the multiple telemetry sources comprise (i) multiple security products from multiple vendors, (ii) multiple product vendors, and (iii) operating system logs;
based on the ingesting, automatically determining, by an auto-analyst engine of the automated threat response, whether a particular network alert event is a security problem; and
based at least in part on the automatically determining whether the particular network alert event is a security problem, taking, by the auto-analyst engine, at least one further first step relating to the particular network alert event,
wherein if the particular network alert event is not a security problem, the at least one further first step comprises:
generating, by the auto-analyst engine, a summary relating to the particular network alert event, wherein the summary comprises an indication of the particular network alert event as a false positive; and
adding the summary to an incident database, and
wherein if the particular network alert event is a security problem, the at least one further first step comprises:
adding, by the auto-analyst engine, information regarding the particular network alert event to the incident database.
10 . The system of claim 9 , wherein the actions further comprise:
automatically determining, by the auto-analyst engine, whether a process is monitored; and
based at least in part on the automatically determining whether the process is monitored, taking, by the auto-analyst engine, at least one further second step relating to the particular network alert event:
wherein if the process is not monitored, the at least one further second step comprises at least one of (i) generating the summary, by the auto-analyst engine, relating to the particular network alert event, wherein the summary comprises the indication of the particular network alert event as a true positive, (ii) adding the summary to the incident database, or (iii) taking a remediation action.
11 . The system of claim 10 , wherein if the particular network alert event is a security problem, the actions further comprise:
determining, by the auto-analyst engine, a process that initiated a connection to the network device, wherein the connection is related to the particular network alert event.
12 . The system of claim 11 , wherein if the process is monitored, the at least one further second step comprises:
determining, by the auto-analyst engine, whether the process is still running,
wherein if the process is not still running, the at least one further second step comprises at least one of (i) generating the summary, by the auto-analyst engine, relating to the particular network alert event, wherein the summary comprises the indication of the particular network alert event as a true positive, (ii) adding the summary to the incident database, or (ii) taking the remediation action.
13 . The system of claim 12 , wherein if the process is still running, the actions further comprise:
at least one of closing, by the auto-analyst engine, the connection to a uniform resource locator (URL), closing, by the auto-analyst engine, a port on which communication is occurring, isolating, by the auto-analyst engine, the network device, discontinuing, by the auto-analyst engine, the process running, or quarantining, by the auto-analyst engine, the network device; and
generating the summary, by the auto-analyst engine, relating to the particular network alert event, wherein the summary comprises the indication of the particular network alert event as a true positive, (ii) adding the summary to the incident database.
14 . The system of claim 9 , wherein the actions further comprise:
obtaining, by the auto-analyst engine, information related to the particular network alert event from at least one of (i) one or more security product application programming interfaces (APIs) or (ii) the incident database.
15 . The system of claim 9 , further comprising:
suggesting, by the auto-analyst engine to a network security entity, further actions that may be taken based at least in part on a history of particular network alert events.
16 . The system of claim 15 , wherein the actions further comprise:
providing, by the auto-analyst engine to a network security entity, the summary; and
receiving, by the auto-analyst engine from the network security entity, feedback related to the summary.
17 . One or more non-transitory computer-readable media storing computer-executable instructions that, when executed by one or more processors, cause the one or more processors to perform actions comprising:
ingesting, at an automated threat response within a network, network alert events from multiple telemetry sources, wherein the multiple telemetry sources comprise (i) multiple security products from multiple vendors, (ii) multiple security product vendors, and (iii) operating system logs;
based on the ingesting, automatically determining, by an auto-analyst engine of the automated threat response, whether a particular network alert event is a security problem; and
based at least in part on the automatically determining whether the particular network alert event is a security problem, taking, by the auto-analyst engine, at least one further first step relating to the particular network alert event,
wherein if the particular network alert event is not a security problem, the at least one further first step comprises:
generating, by the auto-analyst engine, a summary relating to the particular network alert event, wherein the summary comprises an indication of the particular network alert event as a false positive; and
adding the summary to an incident database, and
wherein if the particular network alert event is a security problem, the at least one further first step comprises:
adding, by the auto-analyst engine, information regarding the particular network alert event to the incident database.
18 . The one or more non-transitory computer-readable media of claim 17 , wherein the actions further comprise:
automatically determining, by the auto-analyst engine, whether a process is monitored; and
based at least in part on the automatically determining whether the process is monitored, taking, by the auto-analyst engine, at least one further second step relating to the particular network alert event:
wherein if the process is not monitored, the at least one further second step comprises at least one of (i) generating the summary, by the auto-analyst engine, relating to the particular network alert event, wherein the summary comprises the indication of the particular network alert event as a true positive, (ii) adding the summary to the incident database, or (iii) taking a remediation action.
19 . The one or more non-transitory computer-readable media of claim 18 , wherein if the particular network alert event is a security problem, the actions further comprise:
determining, by the auto-analyst engine, a process that initiated a connection to the network device, wherein the connection is related to the particular network alert event.
20 . The one or more non-transitory computer-readable media of claim 19 , wherein if the process is monitored, the at least one further second step comprises:
determining, by the auto-analyst engine, whether the process is still running,
wherein if the process is not still running, the at least one further second step comprises at least one of (i) generating the summary, by the auto-analyst engine, relating to the particular network alert event, wherein the summary comprises the indication of the particular network alert event as a true positive, (ii) adding the summary to the incident database, or (ii) taking the remediation action, and
wherein if the process is still running, the actions further comprise:
discontinuing, by the auto-analyst engine, the process running; and
generating the summary, by the auto-analyst engine, relating to the particular network alert event, wherein the summary comprises the indication of the particular network alert event as a true positive, (ii) adding the summary to the incident database.