IP Library Granted Patent US 11,019,092
Granted Patent B2
US 11,019,092 · App. 14/677,493 · Granted May 25, 2021

Learning based security threat containment

Inventors: Sourabh Satish (Fremont, CA); Oliver Friedrichs (Woodside, CA); Atif Mahadik (Fremont, CA); Govind Salinas (Sunnyvale, CA)
Assignee: Splunk. Inc.
H04L63/1441G06F16/285G06F21/554H04L63/0236H04L63/1416H04L63/1425H04L63/1433H04L63/20H04L47/2425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,019,092
App. No.
14/677,493
Granted
May 25, 2021
Kind
B2
Abstract

Systems, methods, and software described herein provide action recommendations to administrators of a computing environment based on effectiveness of previously implemented actions. In one example, an advisement system identifies a security incident for an asset in the computing environment, and obtains enrichment information for the incident. Based on the enrichment information a rule set and associated recommended security actions are identified for the incident. Once the recommended security actions are identified, a subset of the action recommendations are organized based on previous action implementations in the computing environment, and the subset is provided to an administrator for selection.

Claims (42)

1. A computer-implemented method performed by an advisement system, the method comprising:

receiving an indication of a security incident involving a computing asset in a networked computing environment comprising a plurality of computing assets;

in response to receiving the indication of the security incident, obtaining enrichment information about the security incident from one or more internet resources;

identifying, based on the enrichment information, a plurality of action recommendations for responding to the security incident;

identifying, for each action recommendation of the plurality of action recommendations, an effectiveness measurement indicating an effectiveness of the action recommendation against past occurrences of the security incident, wherein the effectiveness measurement of an action recommendation of the plurality of action recommendations against past occurrences of the security incident is generated by measuring an amount of data lost after execution of the action recommendation;

identifying a subset of action recommendations from the plurality of action recommendations based on a respective effectiveness measurement of each action recommendation of the plurality of action recommendations, wherein the subset of action recommendations is less than the plurality of action recommendations;

receiving input selecting an action recommendation from the subset of action recommendations; and

implementing the action recommendation in the networked computing environment.

2. The method of claim 1 , wherein identifying the effectiveness measurement indicating an effectiveness of the action recommendation against past occurrences of the security incident includes measuring an effectiveness of an instance of a user selecting the action recommendation.

3. The method of claim 1 , wherein identifying the effectiveness measurement indicating an effectiveness of the action recommendation against past occurrences of the security incident includes measuring an effectiveness of an automatic implementation of the action recommendation.

4. The method of claim 1 , wherein the indication of the security incident comprises at least one of: an internet protocol (IP) address related to the security incident, an identity of the computing asset affected by the security incident, or a process name related to the security incident.

5. The method of claim 4 , wherein the one or more internet resources includes a database or a website associated with the security incident.

6. The method of claim 1 , further comprising providing a hierarchy of the subset of action recommendations to a user via an administration console of the advisement system.

7. The method of claim 1 , further comprising causing display of a user interface including a representation of a hierarchy of the subset of action recommendations.

8. The method of claim 1 , wherein the effectiveness measurement is further generated by measuring whether the action recommendation removed threats associated with the security incident.

9. A non-transitory computer readable storage medium having instructions stored thereon which, when executed by one more processors, cause performance of operations comprising:

receiving an indication of a security incident involving a computing asset in a networked computing environment comprising a plurality of computing assets;

in response to receiving the indication of the security incident, obtaining enrichment information about the security incident from one or more internet resources;

identifying, based on the enrichment information, a plurality of action recommendations for responding to the security incident;

identifying, for each action recommendation of the plurality of action recommendations, an effectiveness measurement indicating an effectiveness of the action recommendation against past occurrences of the security incident, wherein the effectiveness measurement of an action recommendation of the plurality of action recommendations against past occurrences of the security incident is generated by measuring an amount of data lost after execution of the action recommendation;

identifying a subset of action recommendations from the plurality of action recommendations based on a respective effectiveness measurement of each action recommendation of the plurality of action recommendations, wherein the subset of action recommendations is less than the plurality of action recommendations;

receiving input selecting an action recommendation from the subset of action recommendations; and

implementing the action recommendation in the networked computing environment.

10. The non-transitory computer readable storage medium of claim 9 , wherein identifying the effectiveness measurement indicating an effectiveness of the action recommendation against past occurrences of the security incident includes measuring an effectiveness of an instance of a user selecting the action recommendation.

11. The non-transitory computer readable storage medium of claim 9 , wherein identifying the effectiveness measurement indicating an effectiveness of the action recommendation against past occurrences of the security incident includes measuring an effectiveness of an automatic implementation of the action recommendation.

12. The non-transitory computer readable storage medium of claim 9 , wherein the indication of the security incident comprises at least one of: an internet protocol (IP) address related to the security incident, an identity of the computing asset affected by the security incident, or a process name related to the security incident.

13. The non-transitory computer readable storage medium of claim 12 , wherein of the one or more internet resources includes a database or a website associated with the security incident.

14. The non-transitory computer readable storage medium of claim 9 , further comprising providing a hierarchy of the subset of action recommendations to a user via an administration console of an advisement system.

15. The non-transitory computer readable storage medium of claim 9 , further comprising causing display of a user interface including a representation of a hierarchy of the subset of action recommendations.

16. The non-transitory computer readable storage medium of claim 9 , wherein the effectiveness measurement is further generated by measuring whether the action recommendation removed threats associated with the security incident.

17. An apparatus, comprising:

one or more processors;

one or more non-transitory computer readable storage media storing instructions which, when executed by the one or more processors, cause the apparatus to:

receive an indication of a security incident involving a computing asset in a networked computing environment comprising a plurality of computing assets;

in response to receiving the indication of the security incident, obtaining enrichment information about the security incident from one or more internet resources;

identify, based on the enrichment information, a plurality of action recommendations for responding to the security incident;

identify, for each action recommendation of the plurality of action recommendations, an effectiveness measurement indicating an effectiveness of the action recommendation against past occurrences of the security incident, wherein the effectiveness measurement of an action recommendation of the plurality of action recommendations against past occurrences of the security incident is generated by measuring an amount of data lost after execution of the action recommendation;

identify a subset of action recommendations from the plurality of action recommendations based on a respective effectiveness measurement of each action recommendation of the plurality of action recommendations, wherein the subset of action recommendations is less than the plurality of action recommendations;

receive input selecting an action recommendation from the subset of action recommendations; and

implement the action recommendation in the networked computing environment.

18. The apparatus of claim 17 , wherein the effectiveness measurement is further generated by measuring whether the action recommendation removed threats associated with the security incident.

19. The apparatus of claim 17 , wherein the instructions, when executed by the one or more processors, further cause the apparatus to cause display of a user interface including a representation of a hierarchy of the subset of action recommendations.

Assignments (4)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 1, 2018
From: PHANTOM CYBER CORPORATION
To: SPLUNK INC.
Reel/Frame 045686/0215 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 2, 2015
From: SATISH, SOURABH; FRIEDRICHS, OLIVER; MAHADIK, ATIF; SALINAS, GOVIND
To: PHANTOM CYBER CORP.
Reel/Frame 035323/0537 →
Continuity (4)
Provisional Application 62087025 · Dec 3, 2014
Provisional Application 62106830 · Jan 23, 2015
Provisional Application 62106837 · Jan 23, 2015
Related Publication 20160164909A1 · Jun 9, 2016
Cited By (3)
US 12,375,522 US 12,580,938 US 12,652,310