首页> 外国专利> Computer-implemented method for determining computer system security threats, security operations center system and computer program product

Computer-implemented method for determining computer system security threats, security operations center system and computer program product

机译:确定计算机系统安全威胁的计算机实现的方法,安全运营中心系统和计算机程序产品

摘要

A computer-implemented method for determining computer system security threats, the computer system including user accounts established on the computer system, the method including the steps of: (i) for a plurality of user accounts, assigning a risk level to each account; (ii) in a time interval, for a plurality of events, wherein each event is linked to a respective user account, assigning an event score relating to deviation from normal behavior of each event with respect to the respective user account; (iii) in the time interval, for the plurality of events, calculating an event importance which is a function of the respective event score and the respective user account risk level; (iv) prioritizing the plurality of events by event importance, and (v) providing a record of the plurality of events, prioritized by event importance.
机译:一种用于确定计算机系统安全威胁的计算机实现的方法,该计算机系统包括在计算机系统上建立的用户帐户,该方法包括以下步骤:(i)对于多个用户帐户,为每个帐户分配风险级别; (ii)在一个时间间隔内,对于多个事件,其中,每个事件都链接到相应的用户帐户,并分配与每个事件相对于相应的用户帐户的偏离每个事件的正常行为的事件分数; (iii)在该时间间隔中,对于多个事件,计算事件重要性,该事件重要性是相应事件得分和相应用户帐户风险等级的函数; (iv)按事件重要性对多个事件进行优先排序,以及(v)按事件重要性对多个事件进行记录。

著录项

  • 公开/公告号US10681060B2

    专利类型

  • 公开/公告日2020-06-09

    原文格式PDF

  • 申请/专利权人 BALABIT S.A.;

    申请/专利号US201515571934

  • 发明设计人 BALAZS SCHEIDLER;MARTON ILLES;

    申请日2015-09-23

  • 分类号H04L29/06;G06N20;G06F21/56;G06F21/57;G06F21/55;G06Q10/06;

  • 国家 US

  • 入库时间 2022-08-21 11:26:17

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号