Security alert customization using local compute environment characteristics
Various embodiments include systems and methods pertaining to a security service platform that detects security threats based on results from multiple security systems. The multiple security systems may each generate and store respective security alerts within a priority object. The priority object may be used to define rules that are based on results from the multiple security systems, including determining groups of security alerts or determining security alert prioritization based on local compute environment characteristics. The security service platform may use the grouping and prioritization information to provide remediation for an alert that indicates a detected cyberattack.
1 . A method comprising:
determining, by a first security system processing first telemetry data associated with a first compute environment, first security alert data comprising a first one or more characteristics;
determining, by the first security system processing the first telemetry data, first prioritization data associated with the first security alert data;
determining, by a second security system processing second telemetry data associated with the first compute environment, second security alert data comprising a second one or more characteristics;
determining, by the second security system processing the second telemetry data, second prioritization data associated with second security alert data;
determining, based on the first security alert data and the second security alert data, third security alert data comprising the first one or more characteristics, the first prioritization data, the second one or more characteristics, and the second prioritization data;
initiating, based on determining the third security alert data, one or more remediation operations;
determining, based on third telemetry data associated with the first compute environment, a fourth security alert; and
determining a security alert group that comprises the third security alert data and the fourth security alert data, wherein the determining the security alert group further comprises:
determining that the third security alert data and the fourth security alert data have been determined within a threshold period of time, and
determining that the third security alert data and the fourth security alert data are related to a same asset or to a same account.
2 . The method of claim 1 , further comprising:
determining, based on the first one or more characteristics, the first prioritization data, the second one or more characteristics, and the second prioritization data, one or more characteristics of a type of remediation operation; and
determining, based on the type of remediation operation, the one or more remediation options.
3 . The method of claim 1 , wherein
the determining the first security alert data further comprises determining that a first one or more detection rules match one or more characteristics of the first telemetry data, and wherein the determining the second security alert data further comprises determining that a second one or more detection rules match one or more characteristics of the second telemetry data.
4 . The method of claim 3 , wherein
at least one of the first one or more detection rules is different from at least one of the second one or more detection rules.
5 . The method of claim 1 , wherein
the third security alert data comprises a priority object indicative of a plurality of output results from a plurality of security systems, and wherein the plurality of output results comprises the first security alert data and the second security alert data.
6 . A system comprising:
a memory storing executable instructions; and
one or more processors that execute the executable instructions to:
determine, by a first security system processing first telemetry data associated with a first compute environment, first security alert data comprising a first one or more characteristics;
determine, by the first security system processing the first telemetry data, first prioritization data associated with the first security alert data;
determine, by a second security system processing second telemetry data associated with the first compute environment, second security alert data comprising a second one or more characteristics;
determine, by the second security system processing the second telemetry data, second prioritization data associated with second security alert data;
determine, based on the first security alert data and the second security alert data, third security alert data comprising the first one or more characteristics, the first prioritization data, the second one or more characteristics, and the second prioritization data;
initiate, based on determining the third security alert data, one or more remediation operations;
determine, based on third telemetry data associated with the first compute environment, a fourth security alert; and
determine a security alert group that comprises the third security alert data and the fourth security alert data, wherein the determining the security alert group further comprises:
determining that the third security alert data and the fourth security alert data have been determined within a threshold period of time, and
determining that the third security alert data and the fourth security alert data are related to a same asset or to a same account.
7 . The system of claim 6 , wherein the one or more processors further execute the executable instructions to:
determine, based on the first one or more characteristics, the first prioritization data, the second one or more characteristics, and the second prioritization data, one or more characteristics of a type of remediation operation; and
determine, based on the type of remediation operation, the one or more remediation options.
8 . The system of claim 6 , wherein
the determining the first security alert data further comprises determining that a first one or more detection rules match one or more characteristics of the first telemetry data, and wherein the determining the second security alert data further comprises determining that a second one or more detection rules match one or more characteristics of the second telemetry data.
9 . The system of claim 8 , wherein
at least one of the first one or more detection rules is different from at least one of the second one or more detection rules.
10 . The system of claim 6 , wherein
the third security alert data comprises a priority object indicative of a plurality of output results from a plurality of security systems, and wherein the plurality of output results comprises the first security alert data and the second security alert data.
11 . One or more non-transitory computer-accessible storage media storing executable instructions that, when executed by one or more processors, cause one or more computer systems to:
determine, by a first security system processing first telemetry data associated with a first compute environment, first security alert data comprising a first one or more characteristics;
determine, by the first security system processing the first telemetry data, first prioritization data associated with the first security alert data;
determine, by a second security system processing second telemetry data associated with the first compute environment, second security alert data comprising a second one or more characteristics;
determine, by the second security system processing the second telemetry data, second prioritization data associated with second security alert data;
determine, based on the first security alert data and the second security alert data, third security alert data comprising the first one or more characteristics, the first prioritization data, the second one or more characteristics, and the second prioritization data;
initiate, based on determining the third security alert data, one or more remediation operations;
determine, based on third telemetry data associated with the first compute environment, a fourth security alert; and
determine a security alert group that comprises the third security alert data and the fourth security alert data, wherein the determining the security alert group further comprises:
determining that the third security alert data and the fourth security alert data have been determined within a threshold period of time, and
determining that the third security alert data and the fourth security alert data are related to a same asset or to a same account.
12 . The one or more non-transitory computer-accessible storage media of claim 11 , wherein the one or more processors, further cause one or more computer systems to:
determine, based on the first one or more characteristics, the first prioritization data, the second one or more characteristics, and the second prioritization data, one or more characteristics of a type of remediation operation; and
determine, based on the type of remediation operation, the one or more remediation options.
13 . The one or more non-transitory computer-accessible storage media of claim 11 , wherein
the determining the first security alert data further comprises determining that a first one or more detection rules match one or more characteristics of the first telemetry data, and wherein the determining the second security alert data further comprises determining that a second one or more detection rules match one or more characteristics of the second telemetry data.
14 . The one or more non-transitory computer-accessible storage media of claim 13 , wherein
the third security alert data comprises a priority object indicative of a plurality of output results from a plurality of security systems, and wherein the plurality of output results comprises the first security alert data and the second security alert data.