×

METHOD FOR AUTOMATED SIEM CUSTOM CORRELATION RULE GENERATION THROUGH INTERACTIVE NETWORK VISUALIZATION

  • US 20180234457A1
  • Filed: 04/21/2017
  • Published: 08/16/2018
  • Est. Priority Date: 02/15/2017
  • Status: Active Grant
First Claim
Patent Images

1. A method for automated Security Information and Event Management (SIEM) custom correlation rule generation, comprising:

  • receiving log data from a plurality of endpoints in a network;

    receiving input data about the network from a user;

    generating a preliminary visualization of the network based on the log data and the input data;

    displaying the preliminary visualization to the user;

    receiving feedback from the user about the preliminary visualization;

    generating, based on the preliminary visualization and the feedback, a visualization of the network;

    automatically generating, based on the visualization, one or more SIEM custom correlation rules;

    receiving event data from the plurality of endpoints;

    applying the one or more SIEM custom correlation rules to the event data in order to determine whether to trigger one or more actions.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×