-
Notifications
You must be signed in to change notification settings - Fork 142
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Added the is_alert flag to the dictionary, the security_control profi…
…le and detection_finding class (#1178) #### Related Issue: 1177 #### Description of changes: Added an attribute, `is_alert` that indicates that an event is an alertable signal, either determined by a security product monitoring activities, via the `Security Control` profile, or by an analytic process on one or more events via the `Detection Finding` class. Note that not all findings are alertable signals, for example `detection_finding`s have Update and Close activities that likely would not be alertable, while Create activities might be. In addition, added the `confidence` and `risk` family of attributes to the `Security Control` profile, and a missing `risk_details` attribute to `data_security_finding`. Earlier versions of the PR, and the Issue #1177 were referring to the `is_alert` attribute as `is_detection` but the meaning of the two are not the same, in particular state changes in `detection_finding` while `finding` events, are not themselves new detections warranting any signaling (unless an incident management system wants to issue update alerts as one example). --------- Signed-off-by: Paul Agbabian <[email protected]> Co-authored-by: Rajas <[email protected]>
- Loading branch information
1 parent
dd62aea
commit a2e0442
Showing
5 changed files
with
105 additions
and
3 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters