Sensor based rules for responding to malicious activity
Abstract
Systems and techniques are provided for creating sensor based rules for detecting and responding to malicious activity. Evidence corresponding to a malicious activity is received. The evidence corresponding to malicious activity is analyzed. Indicators are identified from the evidence. The indicators are extracted from the evidence. It is determined that an action to mitigate or detect a threat needs to be taken based on the indicators and evidence. A sensor to employ the prescribed action is identified. Whether a sensor based rule meets a threshold requirement is validated. A configuration file used to task the sensor based rule to the identified sensor is created. The number of sensor based rule triggers is tracked.
Claims
exact text as granted — not AI-modified1 . A computer-implemented method comprising: receiving, at a computing device, an evidence corresponding to a malicious activity, wherein the evidence is received from an external computing device and is stored in a file by the computing device; extracting, by the computing device with an extraction engine, one or more indicators from the evidence by analyzing the contents of the file in which the evidence was stored; creating, with the computing device, a sensor based rule from the one or more indicators; identifying which sensor type to employ for mitigation based on the indicator type; and creating a sensor configuration for tasking the sensor based rule to a sensor of an intrusion prevention or intrusion detection system, wherein the sensor monitors one or more of the computer system and a network infrastructure to which the computer system is connected, and wherein the sensor is of the identified sensor type.
Join the waitlist — get patent alerts
Track US2020153865A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.