Machine learning model for recommending security threat response actions
A security threat detection and response (STDR) system is disclosed capable of recommending actions for handling security events detected in a computer network. In embodiments, user actions taken via the graphical user interface of the system are recorded. The records are used as training data to train a machine learning model to recommend actions for different types of security events to subsequent users. The training may be performed online, so that the model continues to learn while it is used to make recommendations. In embodiments, the model may infer a priority of a recommended action based on observation data such as how quickly an action is taken, the order in which actions are taken, and the popularity of the action for the particular security event. In embodiments, the model may be configured to recommend actions that are new to the system or actions for new types of security events.
1 . A system, comprising: one or more computer devices that implement a security threat detection and response (STDR) system and store program instructions executable to cause the STDR system to:
receive observation data collected from a computer network;
detect, based on the observation data, a security event in the computer network indicating a potential security threat;
generate a feature vector that represents the security event;
execute a machine learning (ML) model on the feature vector to generate at least one response action for the security event,
wherein: the ML model is a self-organizing map (SOM) trained using one or more ML techniques to output response actions for different security events, the SOM comprises a grid of neuron units individually mapped to respective action groups of one or more response actions, and response actions in an action group have respective priority values that are adjusted during training of the SOM, and based on user feedback and on training data associated with previous response actions taken via the STDR system for previous security events;
generate graphical user interface (GUI) data to present, via a GUI of the STDR system, the security event and the response action as a recommended action; and in response to user input via the GUI, execute the recommended action via the STDR system.
2 . The system of claim 1 , wherein:
the program instructions are executable to cause the STDR system to monitor a plurality of client networks for security threats, including the computer network;
the observation data includes two or more of activity data, traffic data, process log data, asset configuration data, and user data about the computer network;
the GUI is implemented at a security operations center (SOC) remote from the client networks; and
the program instructions are executable to cause the STDR to initiate response actions in response to the security threats, including investigative actions and remediation actions.
3 . The system of claim 1 , wherein a mapping of the neuron units to the respective action groups is stored as a hash table.
4 . The system of claim 1 , wherein:
the priority values are adjusted based on user feedback data with respect to recommendations outputted by the SOM.
5 . The system of claim 1 , wherein the program instructions are executable to cause the STDR system to initiate the recommended action via an application programming interface (API) of the STDR system.
6 . The system of claim 1 , wherein:
the GUI is implemented as a web-based interface presented in a web browser;
the program instructions are executable to cause the STDR system to present, via the web-based interface, a recommended script of a sequence of actions for the security event; and
the sequence of actions includes interactive actions to be taken via the web-based interface.
7 . The system of claim 6 , wherein the recommended action includes a web request in a Hypertext Transport Protocol (HTTP) request to read or update one or more web resources.
8 . The system of claim 6 , wherein the recommended action includes an interaction with a user control element or an area of the web-based interface.
9 . The system of claim 6 , wherein the recommended action includes a navigation to new webpage in the web-based interface or a change of a Document Object Model (DOM) data in a webpage in the web-based interface.
10 . The system of claim 6 , wherein the sequence of actions includes two or more of:
(a) navigating to a webpage associated with a machine or user indicated in the event,
(b) copying or pasting a piece of information from or to the web-based interface,
(c) clicking a button in the web-based interface,
(d) navigating to a webpage for performing a type of log search associated with the machine or user,
(e) composing a query using information copied from the web-based interface,
(f) composing a textual report of an investigation of the security event, and
(g) creating a ticket to initiate a remedial action on the machine or user.
11 . A method, comprising: performing, by a security threat detection and response (STDR) system implemented by one or more computer devices: receiving observation data collected from a computer network;
detecting, based on the observation data, a security event indicating a potential security threat in the computer network;
generating a feature vector that represents the security event; executing a machine learning (ML) model on the feature vector to obtain at least one response action for the security event, wherein: the ML model is a self-organizing map (SOM) trained using one or more ML techniques to output response actions for different security events, the SOM comprises a grid of neuron units individually mapped to respective action groups of one or more response actions, and response actions in an action group have respective priority values that are adjusted during training of the SOM, based on user feedback and training data associated with previous response actions taken via the STDR system for previous security events;
generating graphical user interface (GUI) data to present, via a GUI of the STDR system, the security event and the response action as a recommended action; and
in response to user input via the GUI, executing the recommended action via the STDR system.
12 . The method of claim 11 , where in the feature vector includes two or more of:
(a) an event category of the security event,
(b) a severity level of the security event,
(c) a machine associated with the security event,
(d) a user associated with the security event,
(e) a time associated with the security event,
(f) a textual description associated with the security event.
13 . The method of claim 12 , where the feature vector includes an indication of investigative state determined based on one or more previous actions performed in response to the security event.
14 . The method of claim 11 , further comprising the STDR system:
presenting via the GUI a priority value of the recommended action, wherein the priority value is based on observed times of when the recommended action is taken in response to previous instances of the security event, relative to other actions.
15 . The method of claim 14 , wherein the priority value is based on a frequency that the recommended action is taken when recommended by the STDR system, wherein the priority is output by the ML model.
16 . The method of claim 11 , wherein the recommended action indicates a search for a particular text in the web-based interface or an interaction with a user control element of the web-based interface, and the method further includes the STDR system highlighting the particular text or the user control element in the web-based interface.
17 . The method of claim 11 , further comprising the STDR system presenting, via the GUI, a user annotation about the recommended action along with the recommended action.
18 . The method of claim 11 , further comprising the STDR system:
presenting, via the GUI, a second recommended action in response to a second security event, wherein the second recommended action is a new type of action implemented by the STDR system or responsive to a new type of security event implemented by the STDR system.
19 . The method of claim 11 , further comprising the STDR system:
performing additional training of the ML model based on user input associated with the recommended action, wherein the additional training changes a recommendation behavior of the ML model for later instances of the security event.
20 . The method of claim 19 , further comprising the STDR system:
present the recommended action with a different priority value for a later instance of the security event, based on the additional training.