首页> 外国专利> SYSTEM AND METHOD ASSOCIATED WITH EXPEDIENT DETECTION AND RECONSTRUCTION OF CYBER EVENTS IN A COMPACT SCENARIO REPRESENTATION USING PROVENANCE TAGS AND CUSTOMIZABLE POLICY

SYSTEM AND METHOD ASSOCIATED WITH EXPEDIENT DETECTION AND RECONSTRUCTION OF CYBER EVENTS IN A COMPACT SCENARIO REPRESENTATION USING PROVENANCE TAGS AND CUSTOMIZABLE POLICY

机译:使用来源标签和可自定义策略的紧凑场景表示中的网络事件的便捷检测和重构的系统和方法

摘要

A system associated with detecting a cyber-attack and reconstructing events associated with a cyber-attack campaign, is disclosed. The system performs various operations that include receiving an audit data stream associated with cyber events. The system identifies trustworthiness values in a portion of data associated with the cyber events and assigns provenance tags to the portion of the data based on the identified trustworthiness values. An initial visual representation is generated based on the assigned provenance tags to the portion of the data. The initial visual representation is condensed based on a backward traversal of the initial visual representation in identifying a shortest path from a suspect node to an entry point node. A scenario visual representation is generated that specifies nodes most relevant to the cyber events associated with the cyber-attack based on the identified shortest path.;A corresponding method and computer-readable medium are also disclosed.
机译:公开了一种与检测网络攻击和重构与网络攻击活动相关的事件相关联的系统。该系统执行各种操作,包括接收与网络事件相关的审核数据流。该系统识别与网络事件相关联的一部分数据中的可信度值,并基于识别出的可信度值将出处标签分配给该数据的一部分。基于为数据部分分配的出处标签生成初始视觉表示。在识别从可疑节点到入口点节点的最短路径时,基于初始视觉表示的向后遍历来压缩初始视觉表示。生成场景视觉表示,该场景视觉表示基于所识别的最短路径来指定与与网络攻击相关的网络事件最相关的节点。还公开了相应的方法和计算机可读介质。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号