US2023081299A1PendingUtilityA1

Corrective action on malware intrusion detection using file introspection

Assignee: VMWARE INCPriority: Dec 17, 2019Filed: Nov 21, 2022Published: Mar 16, 2023
Est. expiryDec 17, 2039(~13.4 yrs left)· nominal 20-yr term from priority
G06N 20/00G06F 21/554G06F 21/568G06N 20/10G06N 5/04
69
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

The disclosure herein describes correlating file events with intrusion detection alerts for corrective action. A monitoring component receives file events from a thin agent. An analysis component analyzes the file events and metadata obtained from the intrusion detection alerts, such as attack type or file name, to correlate a set of file events to at least one detected action (intrusion) described in the alert. A recommendation component identifies one or more options, including one or more corrective actions, which are applicable for remediating the alert. The set of options includes a recommended action from two or more possible corrective actions. The set of options are output or displayed to the user. The user selects which option/action to perform in response to the alert. In some examples, an automatic response is performed without user selection with respect to selected types of alerts, detected action(s), selected file(s) or other user-generated criteria.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A computerized method for managing corrective action intrusion detection alerts, the computerized method comprising:
 correlating one or more file events with a malware alert;   generating event-correlation data based on the correlation;   applying one or more rules to the event-correlation data for generating one or more options applicable to the malware alert;   selecting a response action from the generated one or more options; and   initiating the selected response action responsive to the malware alert.   
     
     
         2 . The computerized method of  claim 1 , wherein the one or more rules include a user-generated rule. 
     
     
         3 . The computerized method of  claim 2 , further comprising updating the user-generated rule based on one or more of dynamic events data and user feedback. 
     
     
         4 . The computerized method of  claim 1 , wherein the one or more rules include an autonomously generated rule by machine learning. 
     
     
         5 . The computerized method of  claim 1 , further comprising:
 refining, by a machine learning component, an accuracy of the one or more options with each malware alert, wherein the machine learning component is trained using historical event resolution data that includes the event-correlation data, the response action, and a result of the response action.   
     
     
         6 . The computerized method of  claim 1 , further comprising:
 determining whether the malware alert is associated with a critical workload; and   in response to determining that the malware alert is associated with the critical workload, initiating an automatic response action.   
     
     
         7 . The computerized method of  claim 1 , further comprising:
 monitoring a plurality of file events to identify the one or more file events associated with the malware alert; and   terminating the monitoring when the malware alert is remediated or a corrective action alert is generated.   
     
     
         8 . A computer system for managing corrective action intrusion detection alerts, said computer system comprising:
 a processor; and   a non-transitory computer-readable medium having stored thereon program code, that upon execution by the processor, causes the processor to:   correlating one or more file events with a malware alert;   generating event-correlation data based on the correlation;   applying one or more rules to the event-correlation data for generating one or more options applicable to the malware alert;   selecting a response action from the generated one or more options; and   initiating the selected response action responsive to the malware alert.   
     
     
         9 . The computer system of  claim 8 , wherein the one or more rules include a user-generated rule. 
     
     
         10 . The computer system of  claim 9 , wherein the program code further causes the processor to update the user-generated rule based on one or more of dynamic events data and user feedback. 
     
     
         11 . The computer system of  claim 8 , wherein the one or more rules include an autonomously generated rule by machine learning. 
     
     
         12 . The computer system of  claim 8 , wherein the program code further causes the processor to:
 refine, by a machine learning component, an accuracy of the one or more options with each malware alert, wherein the machine learning component is trained using historical event resolution data that includes the event-correlation data, the response action, and a result of the response action.   
     
     
         13 . The computer system of  claim 8 , wherein the program code further causes the processor to:
 determine whether the malware alert is associated with a critical workload; and   in response to determining that the malware alert is associated with the critical workload, initiate an automatic response action.   
     
     
         14 . The computer system of  claim 8 , wherein the program code further causes the processor to:
 monitor a plurality of file events to identify the one or more file events associated with the malware alert; and   terminate the monitoring when the malware alert is remediated or a corrective action alert is generated.   
     
     
         15 . A non-transitory computer readable storage medium having stored thereon program code executable by a processor, the program code embodying a method comprising:
 correlating one or more file events with a malware alert;   generating event-correlation data based on the correlation;   applying one or more rules to the event-correlation data for generating one or more options applicable to the malware alert;   selecting a response action from the generated one or more options; and   initiating the selected response action responsive to the malware alert.   
     
     
         16 . The non-transitory computer readable storage medium of  claim 15 , wherein the one or more rules include a user-generated rule, wherein the program code embodying the method further comprising updating the user-generated rule based on one or more of dynamic events data and user feedback. 
     
     
         17 . The non-transitory computer readable storage medium of  claim 15 , wherein the one or more rules include an autonomously generated rule by machine learning. 
     
     
         18 . The non-transitory computer readable storage medium of  claim 15 , wherein the program code embodying the method further comprising:
 refining, by a machine learning component, an accuracy of the one or more options with each malware alert, wherein the machine learning component is trained using historical event resolution data that includes the event-correlation data, the response action, and a result of the response action.   
     
     
         19 . The non-transitory computer readable storage medium of  claim 15 , wherein the program code embodying the method further comprising:
 determining whether the malware alert is associated with a critical workload; and   in response to determining that the malware alert is associated with the critical workload, initiating an automatic response action.   
     
     
         20 . The non-transitory computer readable storage medium of  claim 15 , wherein the program code embodying the method further comprising:
 monitoring a plurality of file events to identify the one or more file events associated with the malware alert; and   terminating the monitoring when the malware alert is remediated or a corrective action alert is generated.

Join the waitlist — get patent alerts

Track US2023081299A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.