THREAT MITIGATION SYSTEM AND METHOD
A computer-implemented method, computer program product and computing system for defining a universal detection rule for execution on a computing platform; processing the universal detection rule to generate a first detection rule that is executable on a first security-relevant subsystem within the computing platform; providing the first detection rule to the first security-relevant subsystem for execution on the first security-relevant subsystem; processing the universal detection rule to generate a second detection rule that is executable on a second security-relevant subsystem within the computing platform; and providing the second detection rule to the second security-relevant subsystem for execution on the first security-relevant subsystem.
1 . A computer-implemented method, executed on a computing device, comprising:
defining a universal detection rule for execution on a computing platform;
processing the universal detection rule to generate a first detection rule that is executable on a first security-relevant subsystem within the computing platform;
providing the first detection rule to the first security-relevant subsystem for execution on the first security-relevant subsystem;
processing the universal detection rule to generate a second detection rule that is executable on a second security-relevant subsystem within the computing platform; and
providing the second detection rule to the second security-relevant subsystem for execution on the second security-relevant subsystem.
2 . The computer-implemented method of claim 1 further comprising:
receiving a first plurality of detection events from the first detection rule executed on the first security-relevant subsystem, wherein the first plurality of detection events concerns a plurality of security events occurring on the first security-relevant subsystem.
3 . The computer-implemented method of claim 2 further comprising:
identifying two or more associated detection events included within the first plurality of detection events; and
grouping the two or more associated detection events to define a security incident.
4 . The computer-implemented method of claim 3 wherein one or more artifacts/log entries are associated with each of first plurality of detection events.
5 . The computer-implemented method of claim 4 wherein:
identifying two or more associated detection events included within the first plurality of detection events includes: identifying two or more detection events included within the first plurality of detection events that have common artifacts/log entries; and
grouping the two or more associated detection events to define a security incident includes: grouping the one or more artifacts/log entries associated with each of the two or more associated detection events to form an artifact/log entry set for the security incident.
6 . The computer-implemented method of claim 1 further comprising:
receiving a second plurality of detection events from the second detection rule executed on the second security-relevant subsystem, wherein the second plurality of detection events concerns a plurality of security events occurring on the second security-relevant subsystem.
7 . The computer-implemented method of claim 6 further comprising:
identifying two or more associated detection events included within the second plurality of detection events; and
grouping the two or more associated detection events to define a security incident.
8 . The computer-implemented method of claim 7 wherein one or more artifacts/log entries are associated with each of second plurality of detection events.
9 . The computer-implemented method of claim 8 wherein:
identifying two or more associated detection events included within the second plurality of detection events includes: identifying two or more detection events included within the second plurality of detection events that have common artifacts/log entries; and
grouping the two or more associated detection events to define a security incident includes: grouping the one or more artifacts/log entries associated with each of the two or more associated detection events to form an artifact/log entry set for the security incident.
10 . The computer-implemented method of claim 1 wherein the first security-relevant subsystem and/or the second security-relevant subsystem includes one or more of:
CDN (i.e., Content Delivery Network) systems;
DAM (i.e., Database Activity Monitoring) systems;
UBA (i.e., User Behavior Analytics) systems;
MDM (i.e., Mobile Device Management) systems;
IAM (i.e., Identity and Access Management) systems;
DNS (i.e., Domain Name Server) systems;
Antivirus systems;
operating systems;
data lakes;
data logs;
security-relevant software applications;
security-relevant hardware systems; and
resources external to the computing platform.
11 . A computer program product residing on a computer readable medium having a plurality of instructions stored thereon which, when executed by a processor, cause the processor to perform operations comprising:
defining a universal detection rule for execution on a computing platform;
processing the universal detection rule to generate a first detection rule that is executable on a first security-relevant subsystem within the computing platform;
providing the first detection rule to the first security-relevant subsystem for execution on the first security-relevant subsystem;
processing the universal detection rule to generate a second detection rule that is executable on a second security-relevant subsystem within the computing platform; and
providing the second detection rule to the second security-relevant subsystem for execution on the second security-relevant subsystem.
12 . The computer program product of claim 11 further comprising:
receiving a first plurality of detection events from the first detection rule executed on the first security-relevant subsystem, wherein the first plurality of detection events concerns a plurality of security events occurring on the first security-relevant subsystem.
13 . The computer program product of claim 12 further comprising:
identifying two or more associated detection events included within the first plurality of detection events; and
grouping the two or more associated detection events to define a security incident.
14 . The computer program product of claim 13 wherein one or more artifacts/log entries are associated with each of first plurality of detection events.
15 . The computer program product of claim 14 wherein:
identifying two or more associated detection events included within the first plurality of detection events includes: identifying two or more detection events included within the first plurality of detection events that have common artifacts/log entries; and
grouping the two or more associated detection events to define a security incident includes: grouping the one or more artifacts/log entries associated with each of the two or more associated detection events to form an artifact/log entry set for the security incident.
16 . The computer program product of claim 11 further comprising:
receiving a second plurality of detection events from the second detection rule executed on the second security-relevant subsystem, wherein the second plurality of detection events concerns a plurality of security events occurring on the second security-relevant subsystem.
17 . The computer program product of claim 16 further comprising:
identifying two or more associated detection events included within the second plurality of detection events; and
grouping the two or more associated detection events to define a security incident.
18 . The computer program product of claim 17 wherein one or more artifacts/log entries are associated with each of second plurality of detection events.
19 . The computer program product of claim 18 wherein:
identifying two or more associated detection events included within the second plurality of detection events includes: identifying two or more detection events included within the second plurality of detection events that have common artifacts/log entries; and
grouping the two or more associated detection events to define a security incident includes: grouping the one or more artifacts/log entries associated with each of the two or more associated detection events to form an artifact/log entry set for the security incident.
20 . The computer program product of claim 11 wherein the first security-relevant subsystem and/or the second security-relevant subsystem includes one or more of:
CDN (i.e., Content Delivery Network) systems;
DAM (i.e., Database Activity Monitoring) systems;
UBA (i.e., User Behavior Analytics) systems;
MDM (i.e., Mobile Device Management) systems;
IAM (i.e., Identity and Access Management) systems;
DNS (i.e., Domain Name Server) systems;
Antivirus systems;
operating systems;
data lakes;
data logs;
security-relevant software applications;
security-relevant hardware systems; and
resources external to the computing platform.
21 . A computing system including a processor and memory configured to perform operations comprising:
defining a universal detection rule for execution on a computing platform;
processing the universal detection rule to generate a first detection rule that is executable on a first security-relevant subsystem within the computing platform;
providing the first detection rule to the first security-relevant subsystem for execution on the first security-relevant subsystem;
processing the universal detection rule to generate a second detection rule that is executable on a second security-relevant subsystem within the computing platform; and
providing the second detection rule to the second security-relevant subsystem for execution on the second security-relevant subsystem.
22 . The computing system of claim 21 further comprising:
receiving a first plurality of detection events from the first detection rule executed on the first security-relevant subsystem, wherein the first plurality of detection events concerns a plurality of security events occurring on the first security-relevant subsystem.
23 . The computing system of claim 22 further comprising:
identifying two or more associated detection events included within the first plurality of detection events; and
grouping the two or more associated detection events to define a security incident.
24 . The computing system of claim 23 wherein one or more artifacts/log entries are associated with each of first plurality of detection events.
25 . The computing system of claim 24 wherein:
identifying two or more associated detection events included within the first plurality of detection events includes: identifying two or more detection events included within the first plurality of detection events that have common artifacts/log entries; and
grouping the two or more associated detection events to define a security incident includes: grouping the one or more artifacts/log entries associated with each of the two or more associated detection events to form an artifact/log entry set for the security incident.
26 . The computing system of claim 21 further comprising:
receiving a second plurality of detection events from the second detection rule executed on the second security-relevant subsystem, wherein the second plurality of detection events concerns a plurality of security events occurring on the second security-relevant subsystem.
27 . The computing system of claim 26 further comprising:
identifying two or more associated detection events included within the second plurality of detection events; and
grouping the two or more associated detection events to define a security incident.
28 . The computing system of claim 27 wherein one or more artifacts/log entries are associated with each of second plurality of detection events.
29 . The computing system of claim 28 wherein:
identifying two or more associated detection events included within the second plurality of detection events includes: identifying two or more detection events included within the second plurality of detection events that have common artifacts/log entries; and
grouping the two or more associated detection events to define a security incident includes: grouping the one or more artifacts/log entries associated with each of the two or more associated detection events to form an artifact/log entry set for the security incident.
30 . The computing system of claim 21 wherein the first security-relevant subsystem and/or the second security-relevant subsystem includes one or more of:
CDN (i.e., Content Delivery Network) systems;
DAM (i.e., Database Activity Monitoring) systems;
UBA (i.e., User Behavior Analytics) systems;
MDM (i.e., Mobile Device Management) systems;
IAM (i.e., Identity and Access Management) systems;
DNS (i.e., Domain Name Server) systems;
Antivirus systems;
operating systems;
data lakes;
data logs;
security-relevant software applications;
security-relevant hardware systems; and
resources external to the computing platform.