FIELD: computer equipment.
SUBSTANCE: invention relates to the computer equipment. Computer-implemented method of automated incident response comprises stages, when receiving from at least one incident from third-party systems, by means of interface module, wherein the incident information comprises at least an incident category, an incident threat level, a host name or address on which the incident occurred and a degree of assurance that the incident is not a false actuation; information on the incident is transmitted to the analytical module, where it is determined whether the incident was previously prevented, and if not, then determining the level of danger of the incident, and if the hazard level exceeds a predetermined threshold, an automated incident response is performed by means of an analytical module and a response module.
EFFECT: technical result consists in implementation of automated response to incident.
19 cl, 4 dwg
Authors
Dates
2020-12-11—Published
2020-03-25—Filed