Microsoft Corporation
Common framework for translating customer feedback to standard and shareable policy changes of cloud threat detection service

Last updated:

Abstract:

Embodiments are provided for integrating feedback into alert managing processes having defined alert policies. These policies define conditions that, when satisfied by certain detected activities, triggers an alert to be sent to a client. A determination is made that a current detected activity does satisfy the condition(s). Subsequent to determining that the set of conditions is satisfied and prior to actually generating the alert, the current detected activity is determined to share a relationship with previously received feedback that caused the alert policy to be modified. After being modified, the alert policy specified whether the alert is to be sent to the client, modified and then sent, suspended, or disabled. The alert is then either generated or refrained from being generated based on the alert policy.

Status:
Grant
Type:

Utility

Filling date:

22 Oct 2019

Issue date:

16 Aug 2022