首页> 外国专利> Intrusion detection system enrichment based on system lifecycle

Intrusion detection system enrichment based on system lifecycle

机译:基于系统生命周期的入侵检测系统充实

摘要

Techniques are described for automatically incorporating lifecycle context information for a secured environment into an intrusion detection system monitoring the secured environment's operations. In one example, an indication of a potentially malicious action occurring in a secured environment monitored by an intrusion detection system is identified. A lifecycle-based context associated with a lifecycle operations manager (LOM) is accessed, where the LOM is responsible for managing lifecycle operations associated with components in the secured environment, and where the context stores information associated with lifecycle operations executed by the LOM. A determination is made as to whether the potentially malicious action associated with the indication is associated with information associated with an executed lifecycle operation stored in the context. In response to determining that a malicious action is associated with a lifecycle operation, a mitigation action associated with the potentially malicious action can be modified.
机译:描述了用于将安全环境的生命周期上下文信息自动合并到监视安全环境的操作的入侵检测系统中的技术。在一个示例中,标识了对在由入侵检测系统监视的安全环境中发生的潜在恶意动作的指示。访问与生命周期操作管理器(LOM)相关联的基于生命周期的上下文,其中LOM负责管理与受保护环境中的组件相关联的生命周期操作,并且上下文存储与由LOM执行的生命周期操作相关的信息。确定与指示相关联的潜在恶意行为是否与与上下文中存储的已执行生命周期操作相关联的信息相关联。响应于确定恶意动作与生命周期操作相关联,可以修改与潜在恶意动作相关联的缓解动作。

著录项

  • 公开/公告号US10671723B2

    专利类型

  • 公开/公告日2020-06-02

    原文格式PDF

  • 申请/专利权人 SAP SE;

    申请/专利号US201715665700

  • 发明设计人 ROUVEN KREBS;JUERGEN FRANK;

    申请日2017-08-01

  • 分类号G06F21/55;H04L29/06;G06F21/57;G06F21/56;H04L12/26;

  • 国家 US

  • 入库时间 2022-08-21 11:28:14

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号