IP Library Granted Patent US 11,469,963
Granted Patent B2
US 11,469,963 · App. 16/594,538 · Granted Oct 11, 2022

Cybersecurity incident response and security operation system employing playbook generation through custom machine learning

Inventors: Dario Valentino Forte (Torre de'Picenardi, IT); Michele Zambelli (Cremona, IT); Vojtech Letal (Pardubice, CZ)
Assignee: Sumo Logic Italy S.p.A
H04L41/12G06F21/62H04L41/0654H04L63/061H04L63/20G06F3/0482H04L41/22
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,469,963
App. No.
16/594,538
Granted
Oct 11, 2022
Kind
B2
Abstract

A new cybersecurity incident is registered at a security incident response platform. At a playbook generation system, details are received of the new cybersecurity incident from the security incident response platform. At least some of the details correspond to a set of features of the new cybersecurity incident. A set or subset of nearest neighbors of the new cybersecurity incident is localized in a feature space. The nearest neighbors of the new cybersecurity incident are other cybersecurity incidents having a distance from the new cybersecurity incident within the feature space that is defined by differences in features of the nearest neighbors with respect to the set of features of the new cybersecurity incident. A custom playbook is created for responding to the new cybersecurity incident. The custom playbook has one or more prescriptive procedures, for responding to the new cybersecurity incident registered by the security incident response platform, that are based on occurrences of prescriptive procedures previously employed in response to the nearest neighbor cybersecurity incidents, and on distances of the nearest neighbors of the new cybersecurity incident in the feature space. A user of the security incident response platform is presented with the custom playbook containing the one or more prescriptive procedures for responding to the new cybersecurity incident. The user of the security incident response platform initiates the one or more prescriptive procedures contained in the custom playbook to respond to the new cybersecurity incident.

Claims (39)

1. A method of responding to cybersecurity incidents, comprising:

at a security incident response platform, registering a new cybersecurity incident;

at a playbook generation system:

receiving details of the new cybersecurity incident from the security incident response platform, at least some of the details corresponding to a set of features of the new cybersecurity incident;

localizing a set of nearest neighbors of the new cybersecurity incident in a feature space, the nearest neighbors of the new cybersecurity incident being other cybersecurity incidents having a distance from the new cybersecurity incident in the feature space within a predetermined value, the distance based on differences in features of the nearest neighbors with respect to the set of features of the new cybersecurity incident;

creating a custom playbook for responding to the new cybersecurity incident, the custom playbook having one or more prescriptive procedures, for responding to the new cybersecurity incident registered by the security incident response platform, that are based on occurrences of prescriptive procedures previously employed in response to the nearest neighbor cybersecurity incidents and based on the distances of the nearest neighbors of the new cybersecurity incident in the feature space;

presenting, on a user interface of the security incident response platform, the custom playbook containing the one or more prescriptive procedures for responding to the new cybersecurity incident; and

initiating, in response to an input received in the user interface of the security incident response platform, the one or more prescriptive procedures contained in the custom playbook to respond to the new cybersecurity incident.

2. A method in accordance with claim 1 , wherein the details of the new cybersecurity incident are contained in fields of a log record, the method further comprising:

transforming, by the playbook generation system, the details contained in at least some of the fields into the set of features.

3. A method in accordance with claim 2 , wherein the at least some of the fields includes a field defining a category of the new cybersecurity incident and at last one filed containing details other than a category of the new cybersecurity incident.

4. A method in accordance with claim 2 , wherein the fields are Common Event Format fields.

5. A method in accordance with claim 2 , wherein the playbook generation system transforms the details into features using Boolean encoding for fields having a type that is Boolean by nature or that represent presence versus absence, and transforms fields having a type that contains a finite set of possible values using one-hot encoding.

6. A method in accordance with claim 1 , wherein the playbook generation system localizes the set of nearest neighbors of the new cybersecurity incident by measuring the distance of the other cybersecurity incidents from the new cybersecurity incident according to a metric applied to the set of features of the other cybersecurity incidents.

7. A method in accordance with claim 6 , wherein the metric applied to the set of features is computed as a weighted of feature values.

8. A method in accordance with claim 7 , wherein the feature values are weighted according to user-settable weights having a numerical value corresponding to relative importance of each feature in the set of features.

9. A method in accordance with claim 1 , wherein the set of nearest neighbors of the new cybersecurity incident has a predefined cardinality K and the playbook generation system localizes K nearest neighbors of the new cybersecurity incident.

10. A method in accordance with claim 1 , wherein the set of nearest neighbors of the new cybersecurity incident has a predefined cardinality K, wherein localizing the set of nearest neighbors further comprises:

if the playbook generation system cannot localize K nearest neighbors of the new cybersecurity incident and one or more incidents in the feature space are identical to the new cybersecurity incident, then identifying the one or more identical incidents as the set of nearest neighbors.

11. A method in accordance with claim 1 , wherein the set of nearest neighbors of the new cybersecurity incident has a predefined cardinality K, wherein localizing the set of nearest neighbors further comprises:

if the playbook generation system localizes K nearest neighbors of the new cybersecurity incident that are identical to the new cybersecurity incident, then identifying as the set of nearest neighbors the K nearest neighbors that are identical to the new cybersecurity incident, each nearest neighbor in the K nearest neighbors having a unique playbook; and

searching for more distant neighbors of the new cybersecurity incident for inclusion in the set of nearest neighbors.

12. A method in accordance with claim 1 , wherein the playbook generation system selects the one or more prescriptive procedures for responding to the new cybersecurity incident based on a relevance of each of the nearest neighbors with respect to the new cybersecurity incident, the relevance being dependent upon the distances of the nearest neighbors from the new cybersecurity incident and ages of the nearest neighbors.

13. A method in accordance with claim 12 , wherein the relevance of each of the nearest neighbors depends upon the distances and the ages of the nearest neighbors according to a user-settable parameter that specifies relative weight given to distance and to age.

14. A method in accordance with claim 1 , wherein the playbook generation system selects the one or more prescriptive procedures in accordance with a score based upon a relevance of each of the nearest neighbors with respect to the new cybersecurity incident, the relevance being dependent upon the distances of the nearest neighbors from the new cybersecurity incident, and based on whether each of the one or more prescriptive procedures was committed in response to each of the nearest neighbors.

15. A method in accordance with claim 14 , further comprising:

at the playbook generation system, generating a plurality of custom playbooks, which are presented on the user interface of the security, incident response platform, the plurality of custom playbooks corresponding to a respective plurality of score thresholds and each of the custom playbooks having one or more prescriptive procedures selected based on the score associated with each prescriptive procedure exceeding the score threshold corresponding to the custom playbook.

16. A method in accordance with claim 1 , further comprising:

at the playbook generation system, recording the new cybersecurity incident in the feature space; and

automatically tying to the new cybersecurity incident the one or more prescriptive procedures received in the user interface in responding to the new cybersecurity incident, thereby automatically updating subsequent recommendations of playbooks for responding to cybersecurity incidents having features similar or identical to the set of features of the new cybersecurity incident.

17. A method in accordance with claim 1 , wherein the set of nearest neighbors comprises a set all neighbors nearest to the new cybersecurity incident in the feature space.

18. A computer-readable, non-transitory, tangible medium comprising software that, when executed by a processor, causes the processor to perform a method of responding to cybersecurity incidents, comprising:

at a security incident response platform, registering a new cybersecurity incident;

at a playbook generation system:

receiving details of the new cybersecurity incident from the security incident response platform, at least some of the details corresponding to a set of features of the new cybersecurity incident;

localizing a set of nearest neighbors of the new cybersecurity incident in a feature space, the nearest neighbors of the new cybersecurity incident being other cybersecurity incidents having a distance from the new cybersecurity incident in the feature space within a predetermined value, the distance based on differences in features of the nearest neighbors with respect to the set of features of the new cybersecurity incident;

creating a custom playbook for responding to the new cybersecurity incident, the custom playbook having one or more prescriptive procedures, for responding to the new cybersecurity incident registered by the security incident response platform, that are based on occurrences of prescriptive procedures previously employed in response to the nearest neighbor cybersecurity incidents and based on the distances of the nearest neighbors of the new cybersecurity incident in the feature space;

presenting, on a user interface of the security incident response platform, the custom playbook containing the one or more prescriptive procedures for responding to the new cybersecurity incident; and

providing an option, in the user interface of the security incident response platform, to initiate the one or more prescriptive procedures contained in the custom playbook to respond to the new cybersecurity incident.

Assignments (4)
PATENT SECURITY AGREEMENT Recorded May 12, 2023
From: SUMO LOGIC, INC.
To: AB PRIVATE CREDIT INVESTORS LLC, AS COLLATERAL AGENT
Reel/Frame 063633/0648 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY NAME PREVIOUSLY RECORDED AT REEL: 057428 FRAME: 0316. ASSIGNOR(S) HEREBY CONFIRMS THE CHANGE OF NAME. Recorded Oct 6, 2022
From: DF LABS S.P.A.
To: SUMO LOGIC, INC.
Reel/Frame 062991/0746 →
CHANGE OF NAME Recorded Sep 9, 2021
From: DF LABS S.P.A.
To: SUMO LOGIC ITALY S.P.A
Reel/Frame 057428/0316 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 7, 2019
From: FORTE, DARIO VALENTINO; ZAMBELLI, MICHELE; LETAL, VOJTECH
To: DFLABS S.P.A.
Reel/Frame 050643/0446 →
Continuity (3)
Continuation 15620439 · Jun 12, 2017
Provisional Application 62490817 · Apr 27, 2017
Related Publication 20200052973A1 · Feb 13, 2020
Cited By (2)
US 12,493,615 US 12,608,370