| CPC G06F 21/554 (2013.01) [G06F 8/70 (2013.01); G06F 16/245 (2019.01); G06F 16/9024 (2019.01); G06F 40/242 (2020.01); G06F 40/30 (2020.01); G06F 2221/033 (2013.01)] | 19 Claims |

|
1. A method for remediating cybersecurity events, comprising:
creating a semantic concepts dictionary, wherein the semantic concepts dictionary defines a plurality of semantic concepts representing characteristics of software components;
creating an entity graph based on a plurality of correlations between entities among a plurality of entities, wherein the entity graph has a plurality of nodes representing respective entities of the plurality of entities, wherein the plurality of entities includes a plurality of software components of a software infrastructure and a plurality of event logic components of cybersecurity event logic deployed with respect to the software infrastructure;
building a knowledge base such that the knowledge base includes the semantic concepts dictionary and the entity graph;
querying the knowledge base using a query generated based on at least one semantic concept and at least one entity-identifying value extracted from cybersecurity event data indicating a cybersecurity event for the software infrastructure, wherein the knowledge base returns at least one query result, wherein the query includes at least one semantic concept and at least one entity-identifying value; and
performing at least one remedial action based on the at least one query result.
|