Rapid7, Inc.
AUTOMATING CLUSTER INTERPRETATION IN SECURITY ENVIRONMENTS
Last updated:
Abstract:
Disclosed herein are methods, systems, and processes to automate cluster interpretation in computing environments to develop targeted remediation security actions. To interpret clusters that are generated by a clustering methodology without subjecting clustered data to classifier-based processing, separation quantifiers that indicate a spread in feature values across clusters are determined and used to discover relative feature importances of features that drive the formation of clusters, permitting a security server to identify features that discriminate between clusters.
Status:
Application
Type:
Utility
Filling date:
10 Dec 2018
Issue date:
11 Jun 2020