Training machine learning models for responding to security threats
A security threat detection and response (STDR) system is disclosed capable of recommending actions for handling security events detected in a computer network. In embodiments, user actions taken via the graphical user interface of the system are recorded. The records are used as training data to train a machine learning model to recommend actions for different types of security events to subsequent users. The training may be performed online, so that the model continues to learn while it is used to make recommendations. In embodiments, the model may infer a priority of a recommended action based on observation data such as how quickly an action is taken, the order in which actions are taken, and the popularity of the action for the particular security event. In embodiments, the model may be configured to recommend actions that are new to the system or actions for new types of security events.
1 . A system, comprising:
one or more computer devices that implement a security threat detection and response (STDR) system, configured to:
present, via a graphical user interface (GUI) of the STDR system, a security event detected in a computer network indicating a potential security threat;
record a sequence of actions taken via the GUI in response to the security event;
generate a feature vector that represents the security event;
generate a training record for a machine learning (ML) model based on the feature vector of the security event and the sequence of actions;
train the ML model based on the training record and using one or more ML techniques, so that the ML model is trained to output recommended actions for different types of security events; and
execute the ML model to recommend, via the GUI, the sequence of actions for a later instance of the security event.
2 . The system of claim 1 , wherein:
the STDR system is configured to monitor a plurality of client networks for security threats, including the computer network; and
the GUI is implemented at a security operations center (SOC) remote from the client networks.
3 . The system of claim 1 , wherein the STDR system is configured to:
perform online training of the ML model based on user input received via the GUI while the ML model provides recommended actions for security events.
4 . The system of claim 3 , wherein the online training changes a recommendation behavior of the ML model to cause the ML model to:
recommend a new action for a type of security event; and
change a priority of a particular action for a type of security event.
5 . The system of claim 1 , wherein the STDR system is configured to:
provide, in the GUI, one or more user control elements to start and stop recording of the action sequence.
6 . The system of claim 1 , wherein the STDR system is configured to:
enable and disable training of the ML model based on configured parameters, including one or more of:
(a) a performance criterion of the ML model,
(b) a list of users whose actions can be used to train the ML model, and
(c) a list of security events for which the ML model can be trained.
7 . The system of claim 1 , wherein the STDR system is configured to:
receive user input specifying a particular action or action sequence to recommend for a particular type of security event.
8 . The system of claim 1 , wherein:
the GUI is implemented as a web-based interface presented in a web browser; and
the sequence of actions includes interactive actions to be taken via the web-based interface.
9 . The system of claim 8 , wherein the sequence of actions includes one or more of:
(a) a web request in a Hypertext Transport Protocol (HTTP) to read or update one or more web resources,
(b) an interaction with a user control element or an area of the web-based interface,
(c) a navigation to new webpage in the web-based interface, and
(d) a change of a Document Object Model (DOM) data in a webpage in the web-based interface.
10 . The system of claim 1 , wherein the machine learned model includes a self-organizing map (SOM).
11 . A method, comprising:
performing, by a security threat detection and response (STDR) system implemented by one or more computer devices:
presenting, via a graphical user interface (GUI) of the STDR system, a security event detected in a computer network indicating a potential security threat;
recording a sequence of actions taken via the GUI in response to the security event;
generating a feature vector that represents the security event;
generating a training record for a machine learning (ML) model based on the feature vector of the security event and the sequence of actions;
training the ML model based on the training record and using one or more ML techniques, so that the ML model is trained to output recommended actions for different types of security events; and
executing the ML model to recommend, via the GUI, the sequence of actions for a later instance of the security event.
12 . The method of claim 11 , further comprising the STDR system:
recording a user annotation that indicates a description of the sequence of action or individual actions in the sequence; and
presenting the user annotation along with the recommendation of the sequence of actions via the GUI.
13 . The method of claim 11 , further comprising the STDR system:
performing online training of the ML model based on training data recorded via the GUI while the ML model provides recommended actions for security events.
14 . The method of claim 13 , wherein the training data includes a new action performed for the security event that is not generated from recorded user actions observed via the GUI.
15 . The method of claim 13 , wherein the training data includes user feedback regarding the recommended sequence of actions.
16 . The method of claim 13 , wherein the training data includes timing data associated with execution of the recommended sequence of actions.
17 . The method of claim 11 , further comprising the STDR system:
storing the ML model in a library of models, wherein different models in the library are assigned to different computer networks, different users or user groups of the STDR system, or different categories of security events.
18 . The method of claim 11 , further comprising the STDR system:
storing the sequence of actions as an action script in a library, wherein individual action scripts in the library are referenced in output of the ML model.
19 . The method of claim 18 , further comprising the STDR system:
storing a definition of a custom action in the library, wherein the custom action is composed of a plurality of primitive actions executable via the GUI.
20 . The method of claim 19 , wherein the custom action includes:
looking up a hostname or network address of a machine in the computer network;
executing a query against data about the machine using the hostname or network address; and
presenting results of the query via the GUI.