IP Library › Granted Patent US 11,563,755
Granted Patent B2
US 11,563,755 · App. 16/827,952 · Granted Jan 24, 2023

Machine-learning based approach for dynamically generating incident-specific playbooks for a security orchestration, automation and response (SOAR) platform

Inventors: Abhishek Narula (Pune, IN); Christopher Carsey (Tucson, AZ); Amit Jain (Pune, IN); Pooja Singh (Pune, IN)
Assignee: Fortinet, Inc.
H04L63/1416G06N5/04G06N20/00H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,563,755
App. No.
16/827,952
Granted
Jan 24, 2023
Kind
B2
Abstract

Systems and methods for a machine-learning based approach for dynamically generating incident-specific playbooks for a security orchestration and automated response (SOAR) platform are provided. The SOAR platform captures information regarding execution of a sequence of actions performed by analysts responsive to a first incident of a first type. The captured information is fed into a machine-learning model. When a second incident, observed by the SOAR platform, is similar in nature to the first incident or the first type a recommended sequence of actions is generated based on the machine-learning model for use by an analyst in connection with responding to the second incident. In response to rejection of the recommended sequence by the analyst, revising the recommended sequence based on input provided by the analyst and storing the revised recommendation sequence in a form of a revised playbook for response to subsequent incidents that are similar to the second incident.

Claims (56)

1. A method for generating a playbook to facilitate incident response by a Security Orchestration, Automation and Response (SOAR) platform, the method comprising:

capturing by the SOAR platform information regarding execution of a sequence of one or more actions performed by one or more analysts responsive to a first incident of a first type, wherein the one or more actions comprise extracting one or more indicators of the first incident, determining a reputation score of each of the one or more indicators using a threat source, analyzing a severity level of the first incident based on the determined reputation score, and processing incident data of the first incident based on the severity level;

feeding the captured information into a machine-learning model;

in response to a second incident observed by the SOAR platform that is similar in nature to the first incident or the first type, generating a recommended sequence of one or more actions for use by an analyst in connection with responding to the second incident, wherein the recommended sequence is generated based on the machine-learning model; and

in response to rejection of the recommended sequence by the analyst, revising the recommended sequence based on input provided by the analyst and storing the revised recommendation sequence in a form of a revised playbook for response to subsequent incidents that are similar to the second incident.

2. The method of claim 1 , further comprising in response to authorization of the recommended sequence by the analyst, programmatically executing the recommended sequence in connection with responding to the second incident and storing the recommended sequence in a form of a playbook for use in connection with responding to subsequent incidents that are similar to the second incident.

3. The method of claim 1 , wherein when the recommended sequence is not authorized by the analyst, the method comprises:

recording investigation notes including prompting the analyst to input a rationale for not authorizing the recommended sequence;

modifying the recommended sequence; and

updating the playbook with the modified recommended sequence.

4. The method of claim 1 , wherein the method further comprises executing the playbook for a subsequent incident of the one or more subsequent incidents when any of the reputation scores of the one or more indicators exceeds a pre-defined or configurable threshold.

5. The method of claim 4 , wherein in response to detection of the subsequent incident, the method further comprises:

determining one or more incidents similar to the subsequent incident using a pre-defined or configurable feature set;

extracting a recommended playbook for the subsequent incident based on any or a combination of a similarity score of each of the one or more incidents similar with the subsequent incident and a frequency score of corresponding playbooks of each of the one or more incidents; and

in response to extracting the recommended playbook from the corresponding playbooks of each of the one or more incidents, incrementing the frequency score of the extracted playbook.

6. The method of claim 5 , wherein in response to modifying the recommended playbook by the analyst, the method comprises:

recording an analyst-defined reasoning associated with modifying of the recommended playbook; and

storing the modified recommended playbook for the one or more incidents that are similar to the subsequent incident.

7. The method of claim 1 , wherein the recommendation sequence is additionally based on the any of a combination of an analyst-defined reasoning associated with decision making, one or more policies defined for SOAR and one or more procedures defined for SOAR.

8. The method of claim 1 , wherein the enforcement engine indicates the recommendation sequence as a suggestion on a graphical user interface (GUI).

9. A non-transitory computer-readable storage medium embodying a set of instructions, which when executed by a processing resource of a Security Orchestration, Automation and Response (SOAR) platform, causes the processing resource to perform a method comprising:

capturing information regarding execution of a sequence of one or more actions performed by one or more analysts responsive to a first incident of a first type, wherein the one or more actions comprise extracting one or more indicators of the first incident, determining a reputation score of each of the one or more indicators using a threat source, analyzing a severity level of the first incident based on the determined reputation score, and processing incident data of the first incident based on the severity level;

feeding the captured information into a machine-learning model;

in response observing a second incident that is similar in nature to the first incident or the first type, generating a recommended sequence of one or more actions for use by an analyst in connection with responding to the second incident, wherein the recommended sequence is generated based on the machine-learning model; and

in response to rejection of the recommended sequence by the analyst, revising the recommended sequence based on input provided by the analyst and storing the revised recommendation sequence in a form of a revised playbook for response to subsequent incidents that are similar to the second incident.

10. The non-transitory computer-readable storage medium of claim 9 , wherein the method further comprises in response to authorization of the recommended sequence by the analyst, programmatically executing the recommended sequence in connection with responding to the second incident and storing the recommended sequence in a form of a playbook for use in connection with responding to subsequent incidents that are similar to the second incident.

11. The non-transitory computer-readable storage medium of claim 9 , wherein when the recommended sequence is not authorized by the analyst, the method further comprises:

recording investigation notes including prompting the analyst to input a rationale for not authorizing the recommended sequence;

modifying the recommended sequence; and

updating the playbook with the modified recommended sequence.

12. The non-transitory computer-readable storage medium of claim 9 , wherein the method further comprises executing the playbook for a subsequent incident of the one or more subsequent incidents when any of the reputation scores of the one or more indicators exceeds a pre-defined or configurable threshold.

13. The non-transitory computer-readable storage medium of claim 12 , wherein in response to detection of the subsequent incident, the method further comprises:

determining one or more incidents similar to the subsequent incident using a pre-defined or configurable feature set;

extracting a recommended playbook for the subsequent incident based on any or a combination of a similarity score of each of the one or more incidents similar with the subsequent incident and a frequency score of corresponding playbooks of each of the one or more incidents; and

in response to extracting the recommended playbook from the corresponding playbooks of each of the one or more incidents, incrementing the frequency score of the extracted playbook.

14. The non-transitory computer-readable storage medium of claim 13 , wherein in response to modifying the recommended playbook by the analyst, the method comprises:

recording an analyst-defined reasoning associated with modifying of the recommended playbook; and

storing the modified recommended playbook for the one or more incidents that are similar to the subsequent incident.

15. The non-transitory computer-readable storage medium of claim 9 , wherein the recommendation sequence is additionally based on the any of a combination of an analyst-defined reasoning associated with decision making, one or more policies defined for SOAR and one or more procedures defined for SOAR.

16. The non-transitory computer-readable storage medium of claim 9 , wherein the recommendation sequence is provided as a suggestion on a graphical user interface (GUI).

17. A system comprising:

a processing resource; and

a non-transitory computer-readable medium, coupled to the processing resource, having stored therein instructions that when executed by the processing resource cause the processing resource to perform a method comprising:

capturing information regarding execution of a sequence of one or more actions performed by one or more analysts responsive to a first incident of a first type, wherein the one or more actions comprise extracting one or more indicators of the first incident, determining a reputation score of each of the one or more indicators using a threat source, analyzing a severity level of the incident based on the determined reputation score, and processing incident data of the first incident based on the severity level;

feeding the captured information into a machine-learning model;

in response observing a second incident that is similar in nature to the first incident or the first type, generating a recommended sequence of one or more actions for use by an analyst in connection with responding to the second incident, wherein the recommended sequence is generated based on the machine-learning model; and

in response to rejection of the recommended sequence by the analyst, revising the recommended sequence based on input provided by the analyst and storing the revised recommendation sequence in a form of a revised playbook for response to subsequent incidents that are similar to the second incident.

18. The system of claim 17 , wherein the method further comprises in response to authorization of the recommended sequence by the analyst, programmatically executing the recommended sequence in connection with responding to the second incident and storing the recommended sequence in a form of a playbook for use in connection with responding to subsequent incidents that are similar to the second incident.

19. The system of claim 17 , wherein when the recommended sequence is not authorized by the analyst, the method further comprises:

recording investigation notes including prompting the analyst to input a rationale for not authorizing the recommended sequence;

modifying the recommended sequence; and

updating the playbook with the modified recommended sequence.

20. The system of claim 19 , wherein in response to detection of the subsequent incident, the method further comprises:

determining one or more incidents similar to the subsequent incident using a pre-defined or configurable feature set;

extracting a recommended playbook for the subsequent incident based on any or a combination of a similarity score of each of the one or more incidents similar with the subsequent incident and a frequency score of corresponding playbooks of each of the one or more incidents; and

in response to extracting the recommended playbook from the corresponding playbooks of each of the one or more incidents, incrementing the frequency score of the extracted playbook.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 24, 2020
From: NARULA, ABHISHEK; CARSEY, CHRISTOPHER; JAIN, AMIT; SINGH, POOJA
To: FORTINET, INC.
Reel/Frame 052207/0728 →
Continuity (1)
Related Publication 20210306352A1 · Sep 30, 2021
Cited By (2)
US 12,399,607 US 12,476,999