Correlating distinct events to detect security threats
Correlating distinct events to detect security threats, including: receiving data describing an event; identifying a plurality of correlated events by correlating, in response to receiving the data describing the event, the event with one or more other events, wherein the one or more other events occurred before the event; determining a severity for the event based on the plurality of correlated events.
1 . A method of correlating distinct events to detect security threats, the method comprising:
receiving data describing an event;
tagging the event using one or more tags based on a standardized taxonomy for categorizing types of activity, the categorization including top level categories each having multiple sub-categories;
identifying a plurality of correlated events by correlating, in response to receiving the data describing the event, the event with one or more other events occurring before the event, the correlation being based at least in part on the one or more event tags; and
determining a severity for the event based on the plurality of correlated events, wherein the sub-categories comprise access token manipulation.
2 . The method of claim 1 , wherein the data describing the event and data describing the one or more other events are received from a plurality of sources.
3 . The method of claim 1 , wherein
determining the severity of the event comprises escalating an initial severity of the event based on one or more other events.
4 . The method of claim 1 , further comprising generating, based on the severity of the event, an alert for the event.
5 . The method of claim 4 , wherein the alert is generated responsive to the severity of the event exceeding any severity of the one or more other events.
6 . The method of claim 1 , wherein the top-level categories comprise at least one of privilege escalation, defense evasion and credential access.
7 . The method of claim 6 , wherein the sub-categories associated with privilege escalation comprise access token manipulation, further comprise: create system process and modify system process.
8 . A method of correlating distinct events to detect security threats, the method comprising:
receiving data describing a first plurality of events associated with an entity;
determining that the first plurality of events satisfies first criteria for correlating the first plurality of events indicated in a first correlation definition; and
generating, in response to the first correlation definition corresponding to a threat incident, a first alert, wherein
determining that the first plurality of events satisfies the first criteria comprises tagging the first plurality of events based on a standardized taxonomy for categorizing types of activity, the categorization including top level categories each having multiple sub-categories, and
the first criteria are based on one or more event tags, wherein the sub-categories comprise access token manipulation.
9 . The method of claim 8 , wherein the first alert comprises one or more descriptors of the threat incident indicated in metadata corresponding to the first correlation definition.
10 . The method of claim 9 , wherein the metadata further comprises a remedial action associated with the threat incident.
11 . The method of claim 10 , further comprising requesting a response indicating whether the remedial action should be implemented.
12 . The method of claim 8 , further comprising:
receiving data describing at least one other event associated with the entity;
determining that a second plurality of events satisfies second criteria for correlating the second plurality of events indicated in a second correlation definition, wherein the second plurality of events comprises the at least one other event and at least a subset of the first plurality of events; and
generating a second alert.
13 . The method of claim 12 , wherein generating the second alert comprises updating the first alert.
14 . The method of claim 12 , wherein generating the second alert is performed in response to a severity associated with the second correlation definition being greater than a severity associated with the first correlation definition.
15 . A computer program product for correlating distinct events to detect security threats, the computer program product disposed on a non-transitory computer readable medium, the computer program product including computer program instructions configurable to carry out the steps of:
receiving data describing a first plurality of events associated with an entity;
determining that the first plurality of events satisfies first criteria for correlating the first plurality of events indicated in a first correlation definition; and
generating, in response to the first correlation definition corresponding to a threat incident, a first alert, wherein
determining that the first plurality of events satisfies the first criteria comprises tagging the first plurality of events based on a standardized taxonomy for categorizing types of activity, the categorization including top level categories each having multiple sub-categories, and
the first criteria are based on one or more event tag, wherein the sub-categories comprise access token manipulation.
16 . The computer program product of claim 15 , wherein the first alert comprises one or more descriptors of the threat incident indicated in metadata corresponding to the first correlation definition.
17 . The computer program product of claim 16 , wherein the metadata further comprises a remedial action associated with the threat incident.
18 . The computer program product of claim 17 , further comprising requesting a response indicating whether the remedial action should be implemented.
19 . The computer program product of claim 15 , further comprising:
receiving data describing at least one other event associated with the entity;
determining that a second plurality of events satisfies second criteria for correlating the second plurality of events indicated in a second correlation definition, wherein the second plurality of events comprises the at least one other event and at least a subset of the first plurality of events; and
generating a second alert, wherein generating the second alert comprises updating the first alert.
20 . The computer program product of claim 19 , wherein generating the second alert is performed in response to a severity associated with the second correlation definition being greater than a severity associated with the first correlation definition.