SCALABLE SECURITY ANALYSIS OF BEHAVIORAL EVENTS
A method of evaluating alerts generated by security agents installed in endpoints includes: receiving a locality-sensitive hash (LSH) value associated with an alert generated by a security agent installed in one of the endpoints; performing a search for centroids that are within a threshold distance from the received LSH value, wherein the centroids are each an LSH value that is representative of one of a plurality of groups of alerts; and assigning a security risk indicator to the alert associated with the received LSH value based on results of the search and transmitting the security risk indicator to a security analytics platform of the endpoints.
1 . A method of evaluating alerts generated by security agents installed in endpoints, said method comprising:
receiving a locality-sensitive hash (LSH) value associated with an alert generated by a security agent installed in one of the endpoints;
performing a search for centroids that are within a threshold distance from the received LSH value, wherein the centroids are each an LSH value that is representative of one of a plurality of groups of alerts; and
assigning a security risk indicator to the alert associated with the received LSH value based on results of the search and transmitting the security risk indicator to a security analytics platform of the endpoints.
2 . The method of claim 1 , further comprising:
transmitting to the security analytics platform profiles associated with the groups of alerts that are represented by the centroids that are within a threshold distance from the received LSH value.
3 . The method of claim 1 , wherein the security risk indicator is a value that indicates whether or not a further investigation of the alert associated with the received LSH value needs to be carried out.
4 . The method of claim 1 , wherein a centroid for each group of alerts has an LSH value that is an average of LSH values of all of the alerts in the group.
5 . The method of claim 1 , further comprising:
comparing profiles associated with the group of alerts that are represented by a centroid that is closest in distance to the received LSH value, wherein
the security risk indicator is assigned further based on results of the comparison.
6 . The method of claim 5 , wherein
the security risk indicator is a value that is assigned to indicate that a further investigation of the alert associated with the received LSH value needs to be carried out if the profiles are not consistent and a prevalence of alerts in the group is less than a minimum threshold.
7 . The method of claim 1 , wherein
the security risk indicator is a value that is assigned to indicate that a further investigation of the alert associated with the received LSH value needs to be carried out if the group of alerts that are represented by a centroid that is closest in distance to the received LSH value includes alerts of the type that are triggered by malicious activities.
8 . The method of claim 1 , wherein the method is carried out by a cloud platform that delivers security services to a plurality of tenants over a network and the endpoints are computing devices communicating with the cloud platform over the network.
9 . The method of claim 8 , wherein the groups of alerts are clusters of alerts that are generated by a clustering algorithm applied to a plurality of alerts previously generated by security agents installed in the endpoints of the plurality of tenants.
10 . A cloud platform for collecting and evaluating alerts generated by security agents installed in endpoints, the cloud platform comprising:
a data store in which locality-sensitive hash (LSH) values associated with a plurality of alerts are stored; and
a processor that is programmed to carry out the steps of:
receiving an LSH value associated with a new alert generated by a security agent installed in one of the endpoints;
performing a search for centroids that are within a threshold distance from the received LSH value, wherein the centroids are each an LSH value that is representative of one of a plurality of groups of the alerts; and
assigning a security risk indicator to the alert associated with the received LSH value based on results of the search and transmitting the security risk indicator to a security analytics platform of the endpoints.
11 . The cloud platform of claim 10 , the steps further comprising:
transmitting to the security analytics platform profiles associated with the groups of alerts that are represented by the centroids that are within a threshold distance from the received LSH value.
12 . The cloud platform of claim 10 , wherein the security risk indicator is a value that indicates whether or not a further investigation of the alert associated with the received LSH value needs to be carried out.
13 . The cloud platform of claim 10 , wherein a centroid for each group of alerts has an LSH value that is an average of LSH values of all of the alerts in the group.
14 . The cloud platform of claim 10 , the steps further comprising:
comparing profiles associated with the group of alerts that are represented by a centroid that is closest in distance to the received LSH value, wherein
the security risk indicator is assigned further based on results of the comparison.
15 . The cloud platform of claim 14 , wherein
the security risk indicator is a value that is assigned to indicate that a further investigation of the alert associated with the received LSH value needs to be carried out if the profiles are not consistent and a prevalence of alerts in the group is less than a minimum threshold.
16 . The cloud platform of claim 10 , wherein
the security risk indicator is a value that is assigned to indicate that a further investigation of the alert associated with the received LSH value needs to be carried out if the group of alerts that are represented by a centroid that is closest in distance to the received LSH value includes alerts of the type that are triggered by malicious activities.
17 . The cloud platform of claim 10 , wherein the method is carried out by a cloud platform that delivers security services to a plurality of tenants over a network and the endpoints are computing devices communicating with the cloud platform over the network.
18 . The cloud platform of claim 17 , wherein the groups of alerts are clusters of alerts that are generated by a clustering algorithm applied to a plurality of alerts previously generated by security agents installed in the endpoints of the plurality of tenants.
19 . A non-transitory computer readable medium comprising instructions that are executable in a processor of a computer system to carry out a method of evaluating alerts generated by security agents installed in endpoints, said method comprising:
receiving a locality-sensitive hash (LSH) value associated with an alert generated by a security agent installed in one of the endpoints;
performing a search for centroids that are within a threshold distance from the received LSH value, wherein the centroids are each an LSH value that is representative of one of a plurality of groups of alerts; and
transmitting to a security analytics platform of the endpoints profiles associated with the groups of alerts that are represented by the centroids that are within a threshold distance from the received LSH value.
20 . The non-transitory computer readable medium of claim 19 , wherein the method further comprises:
assigning a security risk indicator to the alert associated with the received LSH value based on results of the search and transmitting the security risk indicator to the security analytics platform.