IP Library Granted Patent US 10,721,266
Granted Patent B1
US 10,721,266 · App. 15/797,496 · Granted Jul 21, 2020

Automated security incident remediation recommender

Inventors: Or Herman-Saffar (Beer-Sheva, IL); Amihai Savir (Sansana, IL); Stephen Todd (Shrewsbury, MA)
Assignee: EMC IP Holding Company LLC
H04L63/1441H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,721,266
App. No.
15/797,496
Granted
Jul 21, 2020
Kind
B1
Abstract

At least one security incident indicative of at least one security event that may impact or has impacted one or more assets associated with an organization is obtained. A remediation recommendation is automatically generated for the security incident based on one or more of: (i) one or more remediation processes associated with one or more security incidents that precede the at least one security incident in time; and (ii) one or more values attributed to the one or more assets of the organization.

Claims (75)

1. A method comprising:

obtaining at least one security incident indicative of at least one security event that may impact or has impacted one or more assets associated with an organization; and

automatically generating a remediation recommendation for the security incident based on: (i) one or more remediation processes associated with historical security incident data of one or more security incidents that precede the at least one security incident in time; and (ii) one or more values attributed to the one or more assets of the organization;

causing presentation of the remediation recommendation for the at least one security incident to at least one security incident responder to implement the remediation recommendation;

receiving feedback data from the at least one security incident responder, the feedback data representative of: (i) identifying similarities between the at least one security incident and the one or more security incidents that precede the at least one security incident in time; and (ii) determining a level of appropriateness of the one or more remediation processes of the remediation recommendation generated for the at least one security incident;

storing the feedback data of the one or more remediation processes of the implemented remediation recommendation with the one or more security incidents that precede the at least one security incident in time; and

updating the historical security incident data with the at least one security incident and the feedback data;

wherein the step of automatically generating a remediation recommendation for the security incident is further based at least in part on a set of generic remediation processes maintained by the organization;

wherein the step of automatically generating a remediation recommendation for the security incident further comprises comparing: (i) one or more features associated with the at least one security event with one or more features associated with each of the one or more security incidents that precede the at least one security incident in time; and (ii) a data value associated with the at least one security event with one or more data values associated with each of the one or more security incidents that precede the at least one security incident in time;

wherein comparing one or more features further comprises comparing similarity between structural features and comparing similarity between textual features; and

wherein the above steps are executed by at least one processing device comprising a processor operatively coupled to a memory.

2. The method of claim 1 , further comprising using the updated historical security incident data for generating at least one subsequent remediation recommendation.

3. The method of claim 1 , wherein:

when the comparing steps indicate that the one or more features and the data value of the at least one security incident are similar to the one or more features and the data value of one of the one or more security incidents that precede the at least one security incident in time;

the remediation recommendation comprises one or more specific actions taken in response to a similar preceding security incident with a severity level corresponding to the similar preceding security incident.

4. The method of claim 1 , wherein:

when the comparing steps indicate that the one or more features of the at least one security incident are similar to the one or more features of one of the one or more security incidents that precede the at least one security incident in time but the data value of the at least one security incident is different than the data value of the preceding security incident;

the remediation recommendation comprises one or more specific actions taken in response to the similar preceding security incident with a severity level corresponding to a remediation process of a similar security incident found in the set of generic remediation processes.

5. The method of claim 4 further comprising executing a text search of the historical security incident data to identify the remediation process of the similar security incident.

6. The method of claim 1 , wherein:

when the comparing steps indicate that the data value of the at least one security incident is similar to the data value of one of the one or more security incidents that precede the at least one security incident in time but the one or more features of the at least one security incident are different than the one or more features of the preceding security incident;

the remediation recommendation comprises one or more specific actions associated with a similar security incident found in the set of generic remediation processes with a severity level corresponding to a remediation process of the similar preceding security incident.

7. The method of claim 1 , wherein:

when the comparing steps indicate that the one or more features and the data value of the at least one security incident are different than the one or more features and the data value of each of the one or more security incidents that precede the at least one security incident in time;

the remediation recommendation comprises one or more specific actions and the severity level associated with a similar security incident found in the set of generic remediation processes.

8. The method of claim 1 , wherein the comparing step comprises use of at least one similarity measure.

9. The method of claim 1 , wherein the step of automatically generating the remediation recommendation further comprises applying a reinforcement learning algorithm on a recommendation model used to generate the remediation recommendation of the at least one security incident.

10. The method of claim 1 , wherein the one or more values attributed to the one or more assets of the organization are computed by one or more valuation algorithms.

11. The method of claim 1 , wherein the one or more values attributed to the one or more assets of the organization are weighted based on security incident remediation criteria.

12. The method of claim 1 , wherein the step of automatically generating a remediation recommendation for the security incident is further based on a representation of information of the one or more assets of the organization.

13. The method of claim 1 , wherein the at least one security incident is reported via a security information and event management tool.

14. The method of claim 1 , further including:

extracting an incident feature vector representative of the at least one security incident;

extracting one or more historical feature vectors representative of the one or more security incidents that precede the at least one security incident in time; and

comparing the incident feature vector with the one or more historical feature vectors to determine if the at least one security incident is similar to the one or more security incidents that precede the at least one security incident in time;

wherein the incident feature vector and the one or more historical feature vectors each comprise structural and textual features.

15. A system comprising:

at least one processor, coupled to a memory, and configured to:

obtain at least one security incident indicative of at least one security event that may impact or has impacted one or more assets associated with an organization;

automatically generate a remediation recommendation for the security incident based on: (i) one or more remediation processes associated with historical security incident data of one or more security incidents that precede the at least one security incident in time; and (ii) one or more values attributed to the one or more assets of the organization;

cause presentation of the remediation recommendation for the at least one security incident to at least one security incident responder to implement the remediation recommendation;

receive feedback data from the at least one security incident responder, the feedback data representative of: (i) identifying similarities between the at least one security incident and the one or more security incidents that precede the at least one security incident in time; and (ii) determining a level of appropriateness of the one or more remediation processes of the remediation recommendation generated for the at least one security incident;

store the feedback data of the one or more remediation processes of the implemented remediation recommendation with the one or more security incidents that precede the at least one security incident in time; and

update the historical security incident data with data representative of the at least one security incident and the feedback data;

wherein automatically generating a remediation recommendation for the security incident is further based at least in part on a set of generic remediation processes maintained by the organization;

wherein automatically generating a remediation recommendation for the security incident further comprises comparing: (i) one or more features associated with the at least one security event with one or more features associated with each of the one or more security incidents that precede the at least one security incident in time; and (ii) a data value associated with the at least one security event with one or more data values associated with each of the one or more security incidents that precede the at least one security incident in time;

wherein comparing one or more features further comprises comparing similarity between structural features and comparing similarity between textual features.

16. The system of claim 15 , wherein the at least one processor if further configured to:

extract an incident feature vector representative of the at least one security incident;

extract one or more historical feature vectors representative of the one or more security incidents that precede the at least one security incident in time; and

compare the incident feature vector with the one or more historical feature vectors to determine if the at least one security incident is similar to the one or more security incidents that precede the at least one security incident in time;

wherein the incident feature vector and the one or more historical feature vectors each comprise structural and textual features.

17. The system of claim 15 , wherein:

when comparing indicates that the one or more features of the at least one security incident are similar to the one or more features of one of the one or more security incidents that precede the at least one security incident in time but the data value of the at least one security incident is different than the data value of the preceding security incident, the remediation recommendation comprises one or more specific actions taken in response to the similar preceding security incident with a severity level corresponding to a remediation process of a similar security incident found in the set of generic remediation processes; and

wherein the at least one processor if further configured to:

execute a text search of the historical security incident data to identify the remediation process of the similar security incident.

18. An article of manufacture comprising a non-transitory processor-readable storage medium having stored therein program code of one or more software programs, wherein the program code when executed by at least one processing device causes said at least one processing device to:

obtain at least one security incident indicative of at least one security event that may impact or has impacted one or more assets associated with an organization;

automatically generate a remediation recommendation for the security incident based on: (i) one or more remediation processes associated with historical security incident data of one or more security incidents that precede the at least one security incident in time; and (ii) one or more values attributed to the one or more assets of the organization;

cause the presentation of the remediation recommendation for the at least one security incident to at least one security incident responder to implement the remediation recommendation;

receive feedback data from the at least one security incident responder, the feedback data representative of: (i) identifying similarities between the at least one security incident and the one or more security incidents that precede the at least one security incident in time; and (ii) determining a level of appropriateness of the one or more remediation processes of the remediation recommendation generated for the at least one security incident;

store the feedback data of the one or more remediation processes of the implemented remediation recommendation with the one or more security incidents that precede the at least one security incident in time; and

update the historical security incident data with data representative of the at least one security incident and the feedback data;

wherein automatically generating a remediation recommendation for the security incident is further based at least in part on a set of generic remediation processes maintained by the organization;

wherein automatically generating a remediation recommendation for the security incident further comprises comparing: (i) one or more features associated with the at least one security event with one or more features associated with each of the one or more security incidents that precede the at least one security incident in time; and (ii) a data value associated with the at least one security event with one or more data values associated with each of the one or more security incidents that precede the at least one security incident in time;

wherein comparing one or more features further comprises comparing similarity between structural features and comparing similarity between textual features.

19. The article of manufacture of claim 18 , wherein the program code when executed by at least one processing device causes said at least one processing device to:

extract an incident feature vector representative of the at least one security incident; and

extract one or more historical feature vectors representative of the one or more security incidents that precede the at least one security incident in time; and

compare the incident feature vector with the one or more historical feature vectors to determine if the at least one security incident is similar to the one or more security incidents that precede the at least one security incident in time;

wherein the incident feature vector and the one or more historical feature vectors each comprise structural and textual features.

20. The article of manufacture of claim 18 , wherein:

when comparing indicates that the one or more features of the at least one security incident are similar to the one or more features of one of the one or more security incidents that precede the at least one security incident in time but the data value of the at least one security incident is different than the data value of the preceding security incident, the remediation recommendation comprises one or more specific actions taken in response to the similar preceding security incident with a severity level corresponding to a remediation process of a similar security incident found in the set of generic remediation processes; and

wherein the program code when executed by at least one processing device causes said at least one processing device further to:

execute a text search of the historical security incident data to identify the remediation process of the similar security incident.

Assignments (8)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (044535/0109) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO WYSE TECHNOLOGY L.L.C.)
Reel/Frame 060753/0414 →
RELEASE OF SECURITY INTEREST AT REEL 044535 FRAME 0001 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058298/0475 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 4, 2019
From: HERMAN-SAFFAR, OR; SAVIR, AMIHAI; TODD, STEPHEN
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 048793/0145 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
PATENT SECURITY AGREEMENT (CREDIT) Recorded Nov 29, 2017
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 044535/0001 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Nov 29, 2017
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 044535/0109 →
Cited By (5)
US 12,199,994 US 12,568,103 US 12,609,958 US 12,659,324 US 12,683,817