ACTION RECOMMENDATIONS FOR COMPUTING ASSETS BASED ON ENRICHMENT INFORMATION
Systems, methods, and software described herein provide security action recommendations to administrators of a computing environment. In one example, a method of operating an advisement system to provide action recommendations in a computing environment includes identifying a security incident for an asset in the computing environment. The method further includes, in response to identifying the security incident, gathering enrichment information about the security incident, and determining a rule set for the security incident based on the enrichment information. The method also provides recommending one or more actions to an administrator based on the rule set.
1 . A method of operating an advisement system to provide action recommendations in a computing environment comprising a plurality of computing devices, the method comprising:
identifying a security incident for an asset in the computing environment;
in response to identifying the security incident, identifying enrichment information about the security incident;
determining a rule set for the security incident based on the enrichment information; and
identifying one or more action recommendations for an administrator based on the rule set.
2 . The method of claim 1 wherein identifying the enrichment information about the security incident comprises identifying the enrichment information in an external database related to the security incident.
3 . The method of claim 1 wherein identifying the security incident for an asset comprises one of receiving the security incident from a security information and event management (SIEM) system or identifying a user defined security incident.
4 . The method of claim 1 wherein the asset comprises one of a router, a switch, a firewall, an operating system, a virtual private network, or an application.
5 . The method of claim 1 wherein identifying the enrichment information about the security incident comprises determining whether one or more approved processes in the computing environment relate to the security incident, and wherein determining the rule set for the security incident based on the enrichment information comprises, if one or more approved processes in the computing environment relate to the security incident, determining the rule set for the security incident based on an effect of the rule set on the one or more approved processes.
6 . The method of claim 1 wherein identifying the security incident for the asset in the computing environment comprises identifying traits related to the security incident, wherein the traits comprise an identifier for the asset, and at least one of an internet protocol (IP) address related to the incident, Uniform Resource Locator (URL) related to the incident, a user name related to the incident, a computing system identifier for the asset, a file name related to the incident, or a service name related to the incident.
7 . The method of claim 1 further comprising generating a display of the one or more recommendations for the administrator.
8 . A computer readable storage medium having instructions stored thereon, that when executed by advisement computing system, direct the advisement computing system to perform a method of providing action recommendations in a computing environment comprising a plurality of computing devices, the method comprising:
identifying a security incident for an asset in the computing environment;
in response to identifying the security incident, identifying enrichment information about the security incident;
determining a rule set for the security incident based on the enrichment information; and
identifying one or more action recommendations for an administrator based on the rule set.
9 . The computer readable storage medium of claim 8 wherein identifying the enrichment information about the security incident comprises identifying the enrichment information in an external database related to the security incident.
10 . The computer readable storage medium of claim 8 , wherein identifying the security incident for an asset comprises one of receiving the security incident from a security information and event management (SIEM) system or identifying a user defined security incident.
11 . The computer readable storage medium of claim 8 , wherein the asset comprises one of a router, a switch, a firewall, an operating system, a virtual private network, or an application.
12 . The computer readable storage medium of claim 8 , wherein identifying the enrichment information about the security incident comprises determining whether one or more approved processes in the computing environment relate to the security incident, and wherein determining the rule set for the security incident based on the enrichment information comprises, if one or more approved processes in the computing environment relate to the security incident, determining the rule set for the security incident based on an effect of the rule set on the one or more approved processes.
13 . The computer readable storage medium of claim 8 , wherein identifying the security incident for the asset in the computing environment comprises identifying traits related to the security incident, wherein the traits comprise an identifier for the asset, and at least one of an internet protocol (IP) address related to the incident, Uniform Resource Locator (URL) related to the incident, a user name related to the incident, a computing system identifier for the asset, a file name related to the incident, or a service name related to the incident.
14 . The computer readable storage medium of claim 8 , wherein the method further comprises generating a display of the one or more recommendations for the administrator.
15 . The computer readable storage medium of claim 9 , wherein the security incident comprises a process, and wherein identifying the enrichment information about the security incident comprises at least determining whether the process is known in the computing environment.
16 . An advisement system to provide security action recommendations in a computing environment, the advisement system comprising:
a communication interface configured to:
receive a security incident for an asset in the computing environment;
a processing system, communicatively coupled to the communication interface, configured to:
in response to receiving the security incident, identify enrichment information about the security incident;
determine a rule set for the security incident based on the enrichment information; and
identify one or more action recommendations for an administrator based on the rule set.
17 . The advisement system of claim 16 wherein the processing system configured to identify the enrichment information about the security incident is configured to identifying the enrichment information in an external database related to the security incident.
18 . The advisement system of claim 16 wherein the asset comprises one of a router, a switch, a firewall, an operating system, a virtual private network, or an application.
19 . The advisement system of claim 16 wherein the security incident comprises a process, and wherein the processing system configured to identify the enrichment information about the security incident is configured to at least determine whether the process is known in the computing environment.
20 . The advisement system of claim 16 wherein the processing system is further configured to generate a display of the one or more recommendations for the administrator.