Intuit Inc.
Method for automated SIEM custom correlation rule generation through interactive network visualization

Last updated:

Abstract:

The present disclosure provides a dynamic method for automated Security Information and Event Management (SIEM) custom correlation rule generation through the use of an interactive network visualization. The visualization is based on log data received from network endpoints and inputs received from a user, and is provided to the user for feedback before the SIEM custom correlation rules are automatically generated based on the visualization. The automatically generated SIEM custom correlation rules are then used to determine whether to trigger actions based on event data received from the network endpoints.

Status:
Grant
Type:

Utility

Filling date:

21 Apr 2017

Issue date:

3 Sep 2019