THREAT MITIGATION SYSTEM AND METHOD
A computer-implemented method, computer program product and computing system for: receiving platform information from a plurality of security-relevant subsystems; processing the platform information to generate processed platform information; identifying more threat-pertinent content included within the processed content; and routing the more threat-pertinent content to a threat analysis engine.
1 .- 21 . (canceled)
22 . A computer-implemented method, executed on a computing device, comprising:
receiving platform information from a plurality of security-relevant subsystems including
processing the platform information to generate processed platform information;
identifying more threat-pertinent content included within the processed platform information;
routing the more threat-pertinent content to a threat analysis engine;
detecting, by the threat analysis engine, a security event based upon the processed content;
assigning a threat level to the security event; and
executing a remedial action plan based upon, at least in part, the assigned threat level.
23 . The computer-implemented method of claim 22 wherein processing the platform information to generate processed platform information includes:
parsing the platform information into a plurality of subcomponents to allow for compensation of varying formats and/or nomenclature.
24 . The computer-implemented method of claim 22 wherein processing the platform information to generate processed platform information includes:
enriching the platform information by including supplemental information from external information resources.
25 . The computer-implemented method of claim 22 wherein processing the platform information to generate processed platform information includes:
utilizing artificial intelligence or machine learning to identify one or more patterns or trends within the platform information.
26 . The computer-implemented method of claim 22 wherein the plurality of security-relevant subsystems includes one or more of:
a data lake;
a data log;
a security-relevant software application;
a security-relevant hardware system; and
a resource external to the computing platform.
27 . The computer-implemented method of claim 22 wherein identifying more threat-pertinent content included within the processed platform information includes:
processing the processed platform information to identify actionable processed platform information that may be used by the threat analysis engine for correlation purposes.
28 . The computer-implemented method of claim 22 wherein the threat analysis engine is a Security Event Information Management (SEIM) system.
29 . A computer program product residing on a non-transitory computer readable medium having a plurality of instructions stored thereon which, when executed by a processor, cause the processor to perform operations comprising:
receiving platform information from a plurality of security-relevant subsystems including
processing the platform information to generate processed platform information;
identifying more threat-pertinent content included within the processed platform information;
routing the more threat-pertinent content to a threat analysis engine;
detecting, by the threat analysis engine, a security event based upon the processed content;
assigning a threat level to the security event; and
executing a remedial action plan based upon, at least in part, the assigned threat level.
30 . The computer program product of claim 29 wherein processing the platform information to generate processed platform information includes:
parsing the platform information into a plurality of subcomponents to allow for compensation of varying formats and/or nomenclature.
31 . The computer program product of claim 29 wherein processing the platform information to generate processed platform information includes:
enriching the platform information by including supplemental information from external information resources.
32 . The computer program product of claim 29 wherein processing the platform information to generate processed platform information includes:
utilizing artificial intelligence or machine learning to identify one or more patterns or trends within the platform information.
33 . The computer program product of claim 29 wherein the plurality of security-relevant subsystems includes one or more of:
a data lake;
a data log;
a security-relevant software application;
a security-relevant hardware system; and
a resource external to the computing platform.
34 . The computer program product of claim 29 wherein identifying more threat-pertinent content included within the processed platform information includes:
processing the processed platform information to identify actionable processed platform information that may be used by the threat analysis engine for correlation purposes.
35 . The computer program product of claim 29 wherein the threat analysis engine is a Security Event Information Management (SEIM) system.
36 . A computing system including a processor and memory configured to perform operations comprising:
receiving platform information from a plurality of security-relevant subsystems including
processing the platform information to generate processed platform information;
identifying more threat-pertinent content included within the processed platform information;
routing the more threat-pertinent content to a threat analysis engine;
detecting, by the threat analysis engine, a security event based upon the processed content;
assigning a threat level to the security event; and
executing a remedial action plan based upon, at least in part, the assigned threat level.
37 . The computing system of claim 36 wherein processing the platform information to generate processed platform information includes:
parsing the platform information into a plurality of subcomponents to allow for compensation of varying formats and/or nomenclature.
38 . The computing system of claim 36 wherein processing the platform information to generate processed platform information includes:
enriching the platform information by including supplemental information from external information resources.
39 . The computing system of claim 36 wherein processing the platform information to generate processed platform information includes:
utilizing artificial intelligence or machine learning to identify one or more patterns or trends within the platform information.
40 . The computing system of claim 36 wherein the plurality of security-relevant subsystems includes one or more of:
a data lake;
a data log;
a security-relevant software application;
a security-relevant hardware system; and
a resource external to the computing platform.
41 . The computing system of claim 36 wherein identifying more threat-pertinent content included within the processed platform information includes:
processing the processed platform information to identify actionable processed platform information that may be used by the threat analysis engine for correlation purposes.
42 . The computing system of claim 36 wherein the threat analysis engine is a Security Event Information Management (SEIM) system.