COLLABORATIVE INVESTIGATION OF SECURITY INDICATORS
Examples relate to collaborative investigation of security indicators. The examples disclosed herein enable presenting, via a user interface, community-based threat information associated with a security indicator to a user. The community-based threat information may comprise investigation results that are obtained from a community of users for the security indicator, and an indicator score that is determined based on the investigation results. The examples further enable obtaining an investigation result from the user and updating the indicator score based on the investigation result.
1 . A method for collaborative investigation of security indicators, the method comprising:
presenting, via a user interface, community-based threat information associated with a security indicator to a user, the community-based threat information comprising investigation results that are obtained from a community of users for the security indicator, and an indicator score that is determined based on the investigation results;
obtaining an investigation result from the user; and
updating the indicator score based on the investigation result.
2 . The method of claim 1 , wherein the community-based threat information comprises information related to the community of users and information related to the security indicator.
3 . The method of claim 2 , further comprising:
receiving, via the user interface, an indication that the security indicator is under investigation by the user; and
updating the investigation status based on the indication that the security indicator is under investigation by the user.
4 . The method of claim 1 , further comprising:
detecting when event data includes an event that matches at least one security indicator of a blacklist; and
generating a security alert based on the detection.
5 . The method of claim 4 , further comprising:
determining whether to remove the security indicator from the blacklist based on the indicator score.
6 . The method of claim 4 , further comprising:
adding the investigation result to the community-based threat information; and
updating the indicator score based on at least one parameter, the at least one parameter comprising the total number of the investigation results, the number of the investigation results indicating that the security indicator is malicious, information related to the community of users, and information related to the security indicator.
7 . A non-transitory machine-readable storage medium comprising instructions executable by a processor of a computing device for collaborative investigation of security indicators, the machine-readable storage medium comprising:
instructions to cause a display of community-based threat information associated with a security indicator, the community-based threat information comprising a collaborative set of investigation results that is obtained from a plurality of users for the security indicator and an indicator score;
instructions to obtain an investigation result indicating whether the security indicator is malicious;
instructions to include the investigation result in the collaborative set; and
instructions to determine the indicator score based on at least one parameter, the at least one parameter comprising the number of the investigation results in the collaborative set that indicate that the security indicator is malicious.
8 . The non-transitory machine-readable storage medium of claim 7 , wherein the at least one parameter comprises the total number of the investigation results in the collaborative set, information related to the plurality of users, and information related to the security indicator.
9 . The non-transitory machine-readable storage medium of claim 7 , further comprising:
instructions to determine whether event data includes an event that corresponds to the security indicator of a blacklist; and
in response to determining that the event data includes the event that corresponds to the security indicator of the blacklist, instructions to generate a security alert.
10 . The non-transitory machine-readable storage medium of claim 7 , further comprising:
instructions to compare the indicator score with a threshold; and
instructions to exclude the security indicator from a blacklist based on the comparison.
11 . The non-transitory machine-readable storage medium of claim 7 , further comprising:
instructions to compare the total number of the investigation results in the collaborative set with a threshold; and
instructions to exclude the security indicator from a blacklist based on the comparison.
12 . A system for collaborative investigation of security indicators comprising:
a processor that:
generates a security alert based on a detection of a security indicator in event data, wherein a blacklist comprises a plurality of security indicators;
in response to the security alert, obtains community-based threat information associated with the security indicator, the community-based threat information comprising a plurality of investigation results that are obtained from a plurality of users for the security indicator and an indicator score that is determined based on the plurality of investigation results;
obtains a new investigation result from a user, the new investigation result indicating whether the security indicator is malicious;
modifies the indicator score based on the new investigation result; and
determines whether to remove the security indicator from the blacklist based on the indicator score.
13 . The system of claim 12 , the processor that:
determines the indicator score based on at least one parameter, the at least one parameter comprising the total number of the plurality of investigation results, the number of the investigation results in the plurality of investigation results that indicate that the security indicator is malicious, information related to the community of users, and information related to the security indicator.
14 . The system of claim 12 , the processor that:
determines whether a change to the community-based threat information occurs; and
in response to determining that the change to the community-based threat information occurs, generates a notification that informs at least one of the plurality of users of the change.
15 . The system of claim 12 , the processor that:
determines a user score associated with the user based on at least one investigation result that the user has previously submitted; and
determines the indicator score based on the user score.