IP Library Granted Patent US 10,341,377
Granted Patent B1
US 10,341,377 · App. 15/292,918 · Granted Jul 2, 2019

Systems and methods for categorizing security incidents

Inventors: Matteo Dell'Amico (Valbonne, FR); Chris Gates (Culver City, CA); Michael Hart (Farmington, CT); Kevin Roundy (Culver City, CA)
Assignee: Symantec Corporation
H04L63/1433G06N20/00H04L63/1441H04L67/42
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,341,377
App. No.
15/292,918
Granted
Jul 2, 2019
Kind
B1
Abstract

The disclosed computer-implemented method for categorizing security incidents may include (i) generating, within a training dataset, a feature vector for each of a group of security incidents, the feature vector including features that describe the security incidents and the features including categories that were previously assigned to the security incidents as labels to describe the security incidents, (ii) training a supervised machine learning function on the training dataset such that the supervised machine learning function learns how to predict an assignment of future categories to future security incidents, (iii) assigning a category to a new security incident by applying the supervised machine learning function to a new feature vector that describes the new security incident, and (iv) notifying a client of the new security incident and the category assigned to the new security incident. Various other methods, systems, and computer-readable media are also disclosed.

Claims (61)

1. A computer-implemented method for categorizing security incidents, at least a portion of the method being performed by a computing device comprising at least one processor, the method comprising:

detecting, by an endpoint computing security program, a threat signature alert triggered at a client machine associated with a client;

identifying historical data that records how the client responded to previous reports of security incidents that were categorized to describe the security incidents;

assigning a category for a new security incident that corresponds to the detected threat signature alert based on an analysis of the historical data indicating that the client responded more frequently to the category than the client responded to a different category;

notifying the client, through an electronically transmitted security incident report, of both the new security incident and the category assigned to the new security incident based on the analysis of the historical data to enable the client to perform a security action to protect itself from a corresponding security threat; and

performing the security action based on the electronically transmitted security incident report, the security action comprising at least one of:

enabling one or more security settings;

applying a patch that is designed to resolve the corresponding security threat;

disabling, powering down, throttling, quarantining, sandboxing, and/or

disconnecting one or more computing resources;

updating a signature threat alert set of definitions; or

upgrading the endpoint computing security program.

2. The computer-implemented method of claim 1 , wherein assigning the category for the new security incident that corresponds to the detected threat signature alert comprises converting a category assignment from the different category to the category.

3. The computer-implemented method of claim 1 , wherein assigning the category is performed after determining that both the category and the different category are candidate categories for the new security incident from among a larger set of categories.

4. The computer-implemented method of claim 1 , further comprising:

assigning the different category to the new security incident in addition to assigning the category; and

increasing a priority of the category over a priority of the different category in reporting the new security incident.

5. A non-transitory computer-readable medium comprising one or more computer-readable instructions that, when executed by at least one processor of a computing device, cause the computing device to:

detect, as part of an endpoint computing security program, a threat signature alert triggered at a client machine associated with a client;

identify historical data that records how the client responded to previous reports of security incidents that were categorized to describe the security incidents;

assign a category for a new security incident that corresponds to the detected threat signature alert based on an analysis of the historical data indicating that the client responded more frequently to the category than the client responded to a different category;

notify the client, through an electronically transmitted security incident report, of both the new security incident and the category assigned to the new security incident based on the analysis of the historical data to enable the client to perform a security action to protect itself from a corresponding security threat; and

perform the security action based on the electronically transmitted security incident report, the security action comprising at least one of:

enabling one or more security settings;

applying a patch that is designed to resolve the corresponding security threat;

disabling, powering down, throttling, quarantining, sandboxing, and/or

disconnecting one or more computing resources;

updating a signature threat alert set of definitions; or

upgrading the endpoint computing security program.

6. The non-transitory computer-readable medium of claim 5 , wherein assigning the category for the new security incident that corresponds to the detected threat signature alert comprises converting a category assignment from the different category to the category.

7. The non-transitory computer-readable medium of claim 5 , wherein assigning the category is performed after determining that both the category and the different category are candidate categories for the new security incident from among a larger set of categories.

8. The non-transitory computer-readable medium of claim 5 , wherein the instructions further cause the computing device to:

assign the different category to the new security incident in addition to assigning the category; and

increase a priority of the category over a priority of the different category in reporting the new security incident.

9. The non-transitory computer-readable medium of claim 5 , wherein identifying the historical data comprises identifying a rate, frequency, absolute number, and/or relative number indicating how the client responded to security incidents that were reported as having a specific category.

10. The non-transitory computer-readable medium of claim 5 , wherein assigning the category comprises selecting the category of the new security incident, based on the analysis of the historical data, in a manner that increases odds of the client actually responding to the new security incident based on a determination that the category assigned to the new security incident is a category to which the client has a relatively higher response rate.

11. A system comprising:

a detection module, stored in memory that detects, as part of an endpoint computing security program, a threat signature alert triggered at a client machine associated with a client;

an identification module, stored in memory, that identifies historical data that records how the client responded to previous reports of security incidents that were categorized to describe the security incidents;

an assignment module, stored in memory, that assigns a category for a new security incident that corresponds to the detected threat signature alert based on an analysis of the historical data indicating that the client responded more frequently to the category than the client responded to a different category;

a notification module, stored in memory, that:

notifies the client, through an electronically transmitted security incident report, of both the new security incident and the category assigned to the new security incident based on the analysis of the historical data; and

commands performance of a security action based on the electronically transmitted security incident report, the security action comprising at least one of:

enabling one or more security settings;

applying a patch that is designed to resolve a corresponding security threat;

disabling, powering down, throttling, quarantining, sandboxing, and/or

disconnecting one or more computing resources;

updating a signature threat alert set of definitions; or

upgrading the endpoint computing security program; and

at least one physical processor configured to execute the detection module, the identification module, the assignment module, and the notification module.

12. The system of claim 11 , wherein the assignment module assigns the category for the new security incident that corresponds to the detected threat signature alert at least in part by converting a category assignment from the different category to the category.

13. The system of claim 11 , wherein the assignment module assigns the category after determining that both the category and the different category are candidate categories for the new security incident from among a larger set of categories.

14. The system of claim 11 , wherein:

the assignment module assigns the different category to the new security incident in addition to assigning the category; and

the assignment module increases a priority of the category over a priority of the different category in reporting the new security incident.

15. The system of claim 11 , wherein the identification module identifies a rate, frequency, absolute number, and/or relative number indicating how the client responded to security incidents that were reported as having a specific category.

16. The system of claim 15 , wherein the identification module derives the rate, frequency, absolute number, and/or relative number by analyzing the historical data.

17. The system of claim 15 , wherein the identification module retrieves the rate, frequency, absolute number, and/or relative number that was previously calculated and stored in computing memory.

18. The system of claim 11 , wherein the identification module computes a relative response rate, frequency, number, and/or amount by subtracting and/or dividing a response rate for one category with the response rate for another category.

19. The system of claim 11 , wherein the identification module compares response rates for two respective categories to derive data on which to base a decision on how to categorize the new security incident.

20. The system of claim 11 , wherein the assignment module selects the category of the new security incident, based on the analysis of the historical data, in a manner that increases odds of the client actually responding to the new security incident based on a determination that the category assigned to the new security incident is a category to which the client has a relatively higher response rate.

Assignments (6)
CHANGE OF NAME Recorded Feb 6, 2023
From: NORTONLIFELOCK INC.
To: GEN DIGITAL INC.
Reel/Frame 062714/0605 →
NOTICE OF SUCCESSION OF AGENCY (REEL 050926 / FRAME 0560) Recorded Sep 13, 2022
From: JPMORGAN CHASE BANK, N.A.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 061422/0371 →
SECURITY AGREEMENT Recorded Sep 13, 2022
From: NORTONLIFELOCK INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062220/0001 →
CHANGE OF NAME Recorded Feb 14, 2020
From: SYMANTEC CORPORATION
To: NORTONLIFELOCK INC.
Reel/Frame 051935/0228 →
SECURITY AGREEMENT Recorded Nov 4, 2019
From: SYMANTEC CORPORATION; BLUE COAT LLC; LIFELOCK, INC,; SYMANTEC OPERATING CORPORATION
To: JPMORGAN, N.A.
Reel/Frame 050926/0560 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 13, 2016
From: DELL'AMICO, MATTEO; GATES, CHRIS; HART, MICHAEL; ROUNDY, KEVIN
To: SYMANTEC CORPORATION
Reel/Frame 040009/0291 →
Cited By (7)
US 12,197,554 US 12,284,202 US 12,355,799 US 12,519,806 US 12,547,735 US 12,621,331 US 12,671,712