Incident descriptions for extended detection and response to security anomalies
Techniques described herein for extended detection and response to security anomalies in computing networks can perform automated analysis of anomalies occurring in different telemetry sources in a computer network, in order to synthesize the anomalies into analyst work units that are surfaced for further analysis by security response teams. Anomalies can initially be processed in order to identify and collect extended anomaly data. The extended anomaly data can then be used to group the anomalies according to a multi-stage grouping process which produces analyst work units. The analyst work units can be processed to produce analyst summaries that assist with analysis and response. Furthermore, the analyst work units can be prioritized for further analysis, and analyst interactions with the prioritized analyst work units can be used to influence subsequent anomaly grouping operations.
1 . A method comprising:
receiving an analyst work unit, the analyst work unit comprising one or more related threat occurrence groups which are related by association with a common group of assets, and each of the one or more related threat occurrence groups comprising multiple detected anomalies detected in a network comprising multiple different computing assets;
identifying, within a data store comprising computing threat information, at least one similar threat that has higher similarity to the analyst work unit than one or more other threats identified in the data store, wherein identifying the at least one similar threat comprises performing a nearest neighbor search on the data store; and
generating an analyst summary of the analyst work unit, wherein generating the analyst summary comprises using a neural network-based generator to process the analyst work unit and the at least one similar threat, and wherein using the neural network-based generator comprises providing, to the neural network-based generator:
a natural language command;
one or more first events based on the analyst work unit;
one or more second events based on the at least one similar threat; and
a risk level based on the at least one similar threat.
2 . The method of claim 1 , wherein the data store further comprises threat response playbook information, and wherein generating the analyst summary further comprises generating, based on the threat response playbook information, a next action recommendation associated with the analyst work unit.
3 . The method of claim 1 , wherein at least generating the analyst summary of the analyst work unit is performed by a server coupled to a local area network, and wherein the local area network further comprises the data store comprising computing threat information.
4 . The method of claim 1 , wherein the neural network-based generator is configured to use at least one of natural language processing or a large language model.
5 . The method of claim 1 , wherein the analyst summary of the analyst work unit comprises one or more different sections corresponding to the one or more first events.
6 . A device comprising:
one or more processors;
one or more computer-readable media storing computer-executable instructions that, when executed by the one or more processors, cause the one or more processors to perform operations comprising:
receiving an analyst work unit, the analyst work unit comprising one or more related threat occurrence groups which are related by association with a common group of assets, and each of the one or more related threat occurrence groups comprising multiple detected anomalies detected in a network comprising multiple different computing assets;
identifying, within a data store comprising computing threat information, at least one similar threat that has higher similarity to the analyst work unit than one or more other threats identified in the data store, wherein identifying the at least one similar threat comprises performing a nearest neighbor search on the data store; and
generating an analyst summary of the analyst work unit, wherein generating the analyst summary comprises using a neural network-based generator to process the analyst work unit and the at least one similar threat, and wherein using the neural network-based generator comprises providing, to the neural network-based generator:
a natural language command;
one or more first events based on the analyst work unit;
one or more second events based on the at least one similar threat; and
a risk level based on the at least one similar threat.
7 . The device of claim 6 , wherein the data store further comprises threat response playbook information, and wherein generating the analyst summary further comprises generating, based on the threat response playbook information, a next action recommendation associated with the analyst work unit.
8 . The device of claim 6 , wherein at least generating the analyst summary of the analyst work unit is performed by a server coupled to a local area network, and wherein the local area network further comprises the data store comprising computing threat information.
9 . The device of claim 6 , wherein the neural network-based generator is configured to use at least one of natural language processing or a large language model.
10 . The device of claim 6 , wherein the analyst summary of the analyst work unit comprises one or more different sections corresponding to the one or more first events.
11 . A method comprising:
receiving anomaly data associated with a security threat in a network, the anomaly data comprising one or more related threat occurrence groups which are related by association with a common group of assets, and each of the one or more related threat occurrence groups comprising multiple detected anomalies detected in a network comprising multiple different computing assets;
identifying, within a threat intelligence data store, at least one similar threat that has higher similarity to the security threat than one or more other threats identified in the threat intelligence data store, wherein identifying the at least one similar threat comprises performing a nearest neighbor search for the security threat in the threat intelligence data store; and
generating an analyst summary of the security threat, wherein generating the analyst summary comprises using a large language model-based generator to process the security threat and the at least one similar threat, and wherein using the large language model-based generator comprises providing, to the large language model-based generator:
a natural language command;
first data based on the security threat;
second data based on the at least one similar threat; and
a risk level based on the at least one similar threat.
12 . The method of claim 11 , wherein the analyst summary comprises one or more different sections corresponding to the second data.
13 . The method of claim 11 , wherein generating the analyst summary further comprises generating a next action recommendation associated with the security threat.
14 . The method of claim 11 , wherein the analyst summary comprises a risk level associated with the security threat.
15 . The method of claim 14 , wherein the risk level associated with the security threat is based at least in part of the risk level associated with the at least one similar threat.
16 . The method of claim 1 , wherein the multiple detected anomalies comprise anomalies detected from at least two different telemetry sources.
17 . The method of claim 1 , wherein the multiple detected anomalies comprise anomalies detected by multiple anomaly detection systems.