Login| Sign Up| Help| Contact|

Patent Searching and Data


Title:
AUTO-DETECTION OF OBSERVABLES AND AUTO-DISPOSITION OF ALERTS IN AN ENDPOINT DETECTION AND RESPONSE (EDR) SYSTEM USING MACHINE LEARNING
Document Type and Number:
WIPO Patent Application WO/2024/093872
Kind Code:
A1
Abstract:
A technique for threat response associated with an endpoint detection and response (EDR) system. The system uses a combination of automated observable detection, threat intelligence enrichment, graph analysis, and supervised machine learning to machine-predict analyst behavior in classifying (as 'true' or 'false' positives) the EDR alerts, and to support either (i) automated suppression of those alerts that the system classifies with sufficient confidence as either true or false, or (ii) for those alerts than cannot be so classified, the providing of recommendations to analysts to facilitate their activities. Auto-detection of observables for graph-based feature detection, together with the automated disposition of alerts where possible greatly reduces overall analyst workload for the EDR system. Further, and even where a machine-based prediction does not have sufficient confidence to enable bypassing the analyst, the system provides the analyst with additional context and enrichment to facilitate expedited (or at least more efficient) alert handling.

Inventors:
BHATIA AANKUR (US)
BASU ABHISHEK (IN)
ARBOS LUIZ MARCEL (PL)
LIGGETT TERRY (US)
PROCTOR KYLE (US)
Application Number:
PCT/CN2023/127565
Publication Date:
May 10, 2024
Filing Date:
October 30, 2023
Export Citation:
Click for automatic bibliography generation   Help
Assignee:
IBM (US)
IBM CHINA CO LTD (CN)
International Classes:
G06F11/22; G06N20/00
Foreign References:
US20180367561A12018-12-20
US20220210168A12022-06-30
US11290483B12022-03-29
US20070209074A12007-09-06
US20200358792A12020-11-12
Attorney, Agent or Firm:
ZHONGZI LAW OFFICE (CN)
Download PDF: