AI 異常偵測與分級
資安AI 持續監控系統指標或交易資料,偵測到異常模式時自動分級處理,低風險自動排除,高風險通知人工介入。
eventagenthuman
為什麼需要 OSOP
異常事件量大且多為誤報,人工逐一檢視不切實際。OSOP 定義清晰的分級邏輯和升級路徑,確保真正的風險不被遺漏,同時記錄每次判定的依據。
Workflow Steps (5)
1
Continuous Monitoring
event2
Anomaly Detection
agent3
Classify Severity
system4
Send Alert
api5
Engineer Decision
humanConnections (4)
Continuous Monitoring→Anomaly Detectionsequential
Anomaly Detection→Classify Severityconditionalanomaly.detected == true
Classify Severity→Send Alertsequential
Send Alert→Engineer Decisionsequential
5
Steps
4
Connections
5
Node Types