SYSTEMS AND METHODS FOR INTELLIGENT CYBERSECURITY ALERT SIMILARITY DETECTION AND CYBERSECURITY ALERT HANDLING
A system and method for generating event-specific handling instructions for accelerating a threat mitigation of a cybersecurity event includes identifying a cybersecurity event; generating a cybersecurity event digest based on the cybersecurity event, computing a cybersecurity hashing-based signature of the cybersecurity event based on the cybersecurity event digest; searching, based on the distinct cybersecurity hashing-based signature of the cybersecurity event, an n-dimensional space comprising a plurality of historical cybersecurity event hashing-based signatures; returning one or more historical cybersecurity events or historical cybersecurity alerts homogeneous to the cybersecurity event based on the search; deriving one or more cybersecurity event-specific handling actions for the cybersecurity event based on identifying a threat handling action corresponding to each of the one or more historical cybersecurity events or historical cybersecurity alerts homogeneous to the cybersecurity event; and executing one or more cybersecurity threat mitigation actions to resolve or mitigate the cybersecurity event.
1 . A method comprising:
obtaining a cybersecurity event comprising a plurality of distinct pieces of event data;
generating a cybersecurity event digest based on the cybersecurity event, wherein generating the cybersecurity event digest includes composing at least one string of text that informs a characterization of the cybersecurity event;
computing, using a hashing algorithm, a hash signature of the cybersecurity event based on providing the cybersecurity event digest to the hashing algorithm;
detecting, based on the hash signature of the cybersecurity event, one or more historical cybersecurity events similar to the cybersecurity event; and
generating a cybersecurity event-specific handling action for the cybersecurity event based on identifying a historical event handling action associated with at least a subset of the one or more historical cybersecurity events.
2 . The method according to claim 1 , further comprising:
executing the cybersecurity event-specific handling action, wherein executing the cybersecurity event-specific handling action includes adding the cybersecurity event to an active, ongoing cybersecurity incident that includes a plurality of distinct cybersecurity events related to the cybersecurity event.
3 . The method according to claim 1 , further comprising:
executing the cybersecurity event-specific handling action, wherein executing the cybersecurity event-specific handling action includes bypassing a cybersecurity investigation that includes executing an automated cybersecurity investigation workflow.
4 . The method according to claim 1 , further comprising:
displaying, by one or more processors, a cybersecurity event similarity user interface element that includes a selectable user interface object that, when selected, executes the cybersecurity event-specific handling action generated for the cybersecurity event.
5 . The method according to claim 4 , further comprising:
while displaying the cybersecurity event similarity user interface element:
receiving an input selecting the selectable user interface object, and
based on receiving the input, executing the cybersecurity event-specific handling action that resolves or mitigates a threat of the cybersecurity event.
6 . A method comprising:
generating, by one or more processors, a cybersecurity alert digest based on a cybersecurity alert, wherein the cybersecurity alert digest includes at least one string of text that describes the cybersecurity alert;
searching, based on a hash signature of the cybersecurity alert digest, a data structure comprising a plurality of historical cybersecurity alert hash signatures that correspond to a plurality of historical cybersecurity alerts;
returning, by the one or more processors, one or more historical cybersecurity alerts based on the search;
identifying, by the one or more processors, a cybersecurity alert-specific handling action for the cybersecurity alert based on an identification of a historical cybersecurity alert handling action associated with at least a subset of the one or more historical cybersecurity alerts; and
executing, by the one or more processors, the cybersecurity alert-specific handling action that resolves or mitigates a threat of the cybersecurity alert.
7 . The method according to claim 6 , wherein:
the cybersecurity alert digest is generated based on an alert type or class of the cybersecurity alert.
8 . The method according to claim 6 , wherein
computing the hash signature of the cybersecurity alert includes computing a hash value for each token included in the cybersecurity alert digest.
9 . The method according to claim 6 , wherein
searching the data structure includes:
assessing the hash signature of the cybersecurity alert against a subset of the plurality of historical cybersecurity alert hash signatures having a same number of tokens as the hash signature of the cybersecurity alert.
10 . The method according to claim 6 , wherein:
the cybersecurity alert includes a plurality of distinct pieces of alert data; and
generating the cybersecurity alert digest includes:
selectively extracting a subset of probative data features from the plurality of distinct pieces of alert data; and
composing the at least one string of text based on the subset of probative data features.
11 . The method according to claim 10 , wherein:
one probative data feature of the subset of probative data features includes a user-specific identifier, and
the method further includes abstracting the user-specific identifier into a non-user specific identifier by generalizing one or more portions of the user-specific identifier, and wherein the cybersecurity alert digest includes the non-user specific identifier.
12 . The method according to claim 6 , further comprising:
displaying, via a web-accessible user interface, a representation of the cybersecurity alert, wherein the representation of the cybersecurity alert includes:
(i) a plurality of distinct pieces of alert data associated with the cybersecurity alert; and
(ii) a cybersecurity alert similarity user interface element.
13 . The method according to claim 12 , wherein:
the cybersecurity alert similarity user interface element includes:
(ii-a) a textual summary comprising both of (1) a numerical quantity of a total number of the one or more historical cybersecurity alerts returned from the search and (2) the historical cybersecurity alert handling action associated with at least the subset of the one or more historical cybersecurity alerts; and
(ii-b) a selectable user interface object that, when selected, executes the cybersecurity alert-specific handling action that resolves or mitigates the threat of the cybersecurity alert.
14 . The method according to claim 13 , further comprising:
while displaying the representation of the cybersecurity alert:
receiving an input selecting the selectable user interface object of the cybersecurity alert similarity user interface element, wherein the cybersecurity alert-specific handling action is executed in response to receiving the input selecting the selectable user interface object of the cybersecurity alert similarity user interface element.
15 . The method according to claim 12 , wherein:
the cybersecurity alert similarity user interface element comprises one or more emphasized regions that visually emphasizes the cybersecurity alert similarity user interface element from portions external to the cybersecurity alert similarity user interface element.
16 . A method comprising:
generating an alert digest based on an alert, wherein the alert digest includes at least one string of text describing the alert;
querying, based on a hash signature of the alert digest, an n-dimensional data structure comprising a plurality of historical alert hash signatures that correspond to a plurality of historical alerts;
returning one or more historical alerts based on the querying;
identifying an alert-specific handling action for the alert based on an identification of a historical handling action associated with at least a subset of the one or more historical alerts; and
executing the alert-specific handling action that resolves or mitigates a threat of the alert.
17 . The method according to claim 16 , further comprising:
automatically assigning a hash signature decay rate to each of the plurality of historical alert hash signatures included in the n-dimensional data structure.
18 . The method according to claim 17 , wherein:
each of the one or more historical alerts returned from the querying is within a target time span based on the hash signature decay rate.
19 . The method according to claim 16 , wherein:
executing the alert-specific handling action that resolves or mitigates the threat of the alert includes:
automatically routing the alert to an alert disposal queue; and
automatically assigning a disposal rationale to the alert based on the alert-specific handling action.
20 . The method according to claim 16 , wherein:
executing the alert-specific handling action that resolves or mitigates the threat of the alert includes routing the alert to an incident queue.