首页> 外文会议>International Conference for Convergence in Technology >Artificial Intelligence based Security Orchestration, Automation and Response System
【24h】

Artificial Intelligence based Security Orchestration, Automation and Response System

机译:基于人工智能的安全编排,自动化和响应系统

获取原文

摘要

Cybersecurity is becoming very crucial in the today's world where technology is now not limited to just computers, smartphones, etc. It is slowly entering into things that are used on daily basis like home appliances, automobiles, etc. Thus, opening a new door for people with wrong intent. With the increase in speed of technology dealing with such issues also requires quick response from security people. Thus, dealing with huge variety of devices quickly will require some extent of automation in this field. Generating threat intelligence automatically and also including those which are multilingual will also add plus point to prevent well known major attacks. Here we are proposing an AI based SOAR system in which the data from various sources like firewalls, IDS, etc. is collected with individual event profiling using a deep-learning detection method. For this the very first step is that the collected data from different sources will be converted into a standardized format i.e. to categorize the data collected from different sources. For standardized format Here our system finds out about the true positive alert for which the appropriate/ needful steps will be taken such as the generation of Indicators of Compromise report and the additional evidences with the help of Security Information and Event Management system. The security alerts will be notified to the security teams with the degree of threat.
机译:网络安全在今天的世界上变得非常重要,在当今技术不仅限于计算机,智能手机等。它正在慢慢进入日常家用电器,汽车等时使用的东西。因此,开启了一个新的门意图错误的人。随着处理此类问题的技术速度的增加,也需要从安全人员的快速反应。因此,快速处理各种各样的设备将需要在这一领域的一定程度的自动化。自动生成威胁情报,还包括多种语言的威胁情报也将添加加点以防止众所周知的主要攻击。在这里,我们正在提出一种基于AI的SOAR系统,其中使用深学习检测方法将来自防火墙,ID等等各种源等的数据进行收集。为此,第一步是来自不同源的收集的数据将被转换为标准化的格式,即分类从不同源收集的数据。对于标准化格式,我们的系统发现了关于将采取适当/需要步骤的真正正警报,例如妥协报告指标以及在安全信息和事件管理系统的帮助下产生额外证据。安全警报将以威胁程度通知给安全团队。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号