首页> 外国专利> Pattern creation in enterprise threat detection

Pattern creation in enterprise threat detection

机译:企业威胁检测中的模式创建

摘要

Search results are received from an initiated free text search of log data from one or more logs, where the free text is performed using search terms entered into a free text search graphical user interface. A set of at least one search result is selected from the search results containing an event desired to be identified in a completed enterprise threat detection (ETD) pattern. A forensic lab application is rendered to complete an ETD pattern. An event filter is added for an event type based on normalized log data to a path. A relative ETD pattern time range is set and an ETD pattern is completed based on the added event filter.
机译:从一个或多个日志的日志数据的已启动自由文本搜索中接收搜索结果,其中使用输入到自由文本搜索图形用户界面中的搜索词来执行自由文本。从包含期望以完整的企业威胁检测(ETD)模式标识的事件的搜索结果中选择一组至少一个搜索结果。呈现法医实验室应用程序以完成ETD模式。基于路径的规范化日志数据,为事件类型添加了事件过滤器。根据添加的事件过滤器,设置相对的ETD模式时间范围,并完成ETD模式。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号