首页> 外国专利> Prioritizing security risks for a computer system based on historical events collected from the computer system environment

Prioritizing security risks for a computer system based on historical events collected from the computer system environment

机译:根据从计算机系统环境中收集的历史事件来确定计算机系统的安全风险的优先级

摘要

A method of identifying security risks in a computer system that includes several computers executing different applications is provided. The method receives event data about threat events associated with a set of applications executing on a set of computers in the computer system. The method, for each event, compares a set of parameters associated with the event with a set of historical parameters maintained for a similar event. The method, based on the comparisons, defines a normality characterization for each event to express a probability of an exploit of the application associated with the event. The method, based on the normality characterization, defines a prioritized display of security risks due to the threat events associated with the set of application.
机译:提供了一种在包括多个执行不同应用程序的计算机的计算机系统中识别安全风险的方法。该方法接收与与在计算机系统中的一组计算机上执行的一组应用程序相关联的威胁事件有关的事件数据。对于每个事件,该方法将与事件关联的一组参数与为类似事件维护的一组历史参数进行比较。该方法基于比较结果,为每个事件定义了正常性表征,以表达利用与该事件相关联的应用程序的可能性。该方法基于正常性表征,定义了由于与应用程序集相关联的威胁事件而导致的安全风险的优先显示。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号