Corrective action on malware intrusion detection using file introspection
Abstract
The disclosure herein describes correlating file events with intrusion detection alerts for corrective action. A monitoring component receives file events from a thin agent. An analysis component analyzes the file events and metadata obtained from the intrusion detection alerts, such as attack type or file name, to correlate a set of file events to at least one detected action (intrusion) described in the alert. A recommendation component identifies one or more options, including one or more corrective actions, which are applicable for remediating the alert. The set of options includes a recommended action from two or more possible corrective actions. The set of options are output or displayed to the user. The user selects which option/action to perform in response to the alert. In some examples, an automatic response is performed without user selection with respect to selected types of alerts, detected action(s), selected file(s) or other user-generated criteria.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A computerized method for managing corrective action intrusion detection alerts, the computerized method comprising:
correlating one or more file events with a malware alert; generating event-correlation data based on the correlation; applying one or more rules to the event-correlation data for generating one or more options applicable to the malware alert; selecting a response action from the generated one or more options; and initiating the selected response action responsive to the malware alert.
2 . The computerized method of claim 1 , wherein the one or more rules include a user-generated rule.
3 . The computerized method of claim 2 , further comprising updating the user-generated rule based on one or more of dynamic events data and user feedback.
4 . The computerized method of claim 1 , wherein the one or more rules include an autonomously generated rule by machine learning.
5 . The computerized method of claim 1 , further comprising:
refining, by a machine learning component, an accuracy of the one or more options with each malware alert, wherein the machine learning component is trained using historical event resolution data that includes the event-correlation data, the response action, and a result of the response action.
6 . The computerized method of claim 1 , further comprising:
determining whether the malware alert is associated with a critical workload; and in response to determining that the malware alert is associated with the critical workload, initiating an automatic response action.
7 . The computerized method of claim 1 , further comprising:
monitoring a plurality of file events to identify the one or more file events associated with the malware alert; and terminating the monitoring when the malware alert is remediated or a corrective action alert is generated.
8 . A computer system for managing corrective action intrusion detection alerts, said computer system comprising:
a processor; and a non-transitory computer-readable medium having stored thereon program code, that upon execution by the processor, causes the processor to: correlating one or more file events with a malware alert; generating event-correlation data based on the correlation; applying one or more rules to the event-correlation data for generating one or more options applicable to the malware alert; selecting a response action from the generated one or more options; and initiating the selected response action responsive to the malware alert.
9 . The computer system of claim 8 , wherein the one or more rules include a user-generated rule.
10 . The computer system of claim 9 , wherein the program code further causes the processor to update the user-generated rule based on one or more of dynamic events data and user feedback.
11 . The computer system of claim 8 , wherein the one or more rules include an autonomously generated rule by machine learning.
12 . The computer system of claim 8 , wherein the program code further causes the processor to:
refine, by a machine learning component, an accuracy of the one or more options with each malware alert, wherein the machine learning component is trained using historical event resolution data that includes the event-correlation data, the response action, and a result of the response action.
13 . The computer system of claim 8 , wherein the program code further causes the processor to:
determine whether the malware alert is associated with a critical workload; and in response to determining that the malware alert is associated with the critical workload, initiate an automatic response action.
14 . The computer system of claim 8 , wherein the program code further causes the processor to:
monitor a plurality of file events to identify the one or more file events associated with the malware alert; and terminate the monitoring when the malware alert is remediated or a corrective action alert is generated.
15 . A non-transitory computer readable storage medium having stored thereon program code executable by a processor, the program code embodying a method comprising:
correlating one or more file events with a malware alert; generating event-correlation data based on the correlation; applying one or more rules to the event-correlation data for generating one or more options applicable to the malware alert; selecting a response action from the generated one or more options; and initiating the selected response action responsive to the malware alert.
16 . The non-transitory computer readable storage medium of claim 15 , wherein the one or more rules include a user-generated rule, wherein the program code embodying the method further comprising updating the user-generated rule based on one or more of dynamic events data and user feedback.
17 . The non-transitory computer readable storage medium of claim 15 , wherein the one or more rules include an autonomously generated rule by machine learning.
18 . The non-transitory computer readable storage medium of claim 15 , wherein the program code embodying the method further comprising:
refining, by a machine learning component, an accuracy of the one or more options with each malware alert, wherein the machine learning component is trained using historical event resolution data that includes the event-correlation data, the response action, and a result of the response action.
19 . The non-transitory computer readable storage medium of claim 15 , wherein the program code embodying the method further comprising:
determining whether the malware alert is associated with a critical workload; and in response to determining that the malware alert is associated with the critical workload, initiating an automatic response action.
20 . The non-transitory computer readable storage medium of claim 15 , wherein the program code embodying the method further comprising:
monitoring a plurality of file events to identify the one or more file events associated with the malware alert; and terminating the monitoring when the malware alert is remediated or a corrective action alert is generated.Join the waitlist — get patent alerts
Track US2023081299A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.