US 12,244,630 B2
Security threat alert analysis and prioritization
Ben Uri Gelman, Burlington, MA (US); Salma Taoufiq, Budapest (HU); Konstantin Berlin, Potomac, MD (US); and Tamás Vörös, Budapest (HU)
Assigned to Sophos Limited, Abingdon (GB)
Filed by Sophos Limited, Abingdon (GB)
Filed on Sep. 30, 2022, as Appl. No. 17/958,147.
Claims priority of provisional application 63/390,913, filed on Jul. 20, 2022.
Claims priority of provisional application 63/339,908, filed on May 9, 2022.
Prior Publication US 2023/0362184 A1, Nov. 9, 2023
Int. Cl. H04L 9/40 (2022.01)
CPC H04L 63/1433 (2013.01) 20 Claims
OG exemplary drawing
 
1. A method for prioritizing security events, comprising:
receiving, by one or more processors of a computer system, a plurality of alerts generated by an endpoint agent response to a detected computer security activity;
extracting, by the one or more processors of a computer system, a plurality of feature vectors from the plurality of alerts;
computing, by the one or more processors of the computer system, a plurality of temporal features from the plurality of alerts, the temporal features including time pattern data of the detected computer security activity;
training, by the one or more processors of the computer system, a first classification model with the plurality of feature vectors;
training, by the one or more processors of the computer system, a second classification model with the plurality of temporal features;
combining, by the one or more processors of the computer system, the first classification model and the second classification model to form an ensemble model that processes an output of each of the first classification model and the second classification model to generate a computed feature result;
generating by the ensemble model from the computed feature result an alert-level risk score corresponding to a severity level value for each alert of the plurality of alerts; and
arranging the plurality of alerts for output to an analyst computer according to the alert-level risk scores.