FIELD: information technology.
SUBSTANCE: invention relates to information security systems. Automatic security incidents investigation system of an automated system contains means of loading data about system events from computer devices connected to the administration server; administration server that includes an event management tool for capturing, logging, analyzing at least one system event from the downloaded data that caused the security incident, and a solution search engine stored in memory and executed on the server of the administration server, the system including an analytical precedent description module for formalizing use cases, search for precedents in the database of precedents, updating of precedents, providing knowledge about the precedents, and precedents database that implements data representation and storage technology in ontology format.
EFFECT: technical result is to increase the effectiveness of automatic investigation of security incidents and, as a result, to reduce the response time to security incidents in an automated system.
2 cl, 2 dwg, 1 tbl
Title | Year | Author | Number |
---|---|---|---|
SYSTEM AND METHOD FOR PREDICTING SIGNS OF INFORMATION SECURITY INCIDENTS IN AUTOMATED CONTROL SYSTEMS | 2023 |
|
RU2815595C1 |
SYSTEM AND METHOD FOR AUTOMATIC INVESTIGATION OF SAFETY INCIDENTS | 2011 |
|
RU2481633C2 |
METHOD AND SYSTEM OF CYBER TRAINING | 2022 |
|
RU2808388C1 |
SYSTEM AND METHOD FOR PREVENTION SAFETY INCIDENTS BASED ON USER DANGER RATING | 2011 |
|
RU2477929C2 |
METHOD FOR ADJUSTING THE PARAMETERS OF A MACHINE LEARNING MODEL IN ORDER TO IDENTIFY FALSE TRIGGERING AND INFORMATION SECURITY INCIDENTS | 2020 |
|
RU2763115C1 |
METHOD FOR PROCESSING INFORMATION SECURITY EVENTS PRIOR TO TRANSMISSION FOR ANALYSIS | 2020 |
|
RU2762528C1 |
SYSTEM AND METHOD OF RAISING SECURITY LEVEL OF COMPUTER SYSTEM | 2011 |
|
RU2460122C1 |
SYSTEM AND METHOD OF CORRELATING EVENTS FOR DETECTING INFORMATION SECURITY INCIDENT | 2019 |
|
RU2739864C1 |
METHOD OF COMPUTER SECURITY DISTRIBUTED EVENTS INVESTIGATION | 2015 |
|
RU2610395C1 |
SYSTEM AND METHOD OF DETECTING THE SIGNS OF COMPUTER ATTACKS | 2017 |
|
RU2661533C1 |
Authors
Dates
2018-08-14—Published
2017-06-21—Filed