首页> 外国专利> Cyber Threat Attenuation Using Multi-source Threat Data Analysis

Cyber Threat Attenuation Using Multi-source Threat Data Analysis

机译:使用多源威胁数据分析的网络威胁衰减

摘要

A cyber threat attenuation system. The system comprises a cyber threat data store, a plurality of sensor control points (SCPs), wherein at least one SCP is located in each local area network (LAN) segment of an enterprise network, and an analytics correlation system (ACS). Each SCP comprises a plurality of sensor applications that analyze data packets transported by the LAN segment in which the SCP is located and transmits a notification identifying the transmitting sensor, an identity of the source of the data packet, an identity of the destination of the data packet, and a notification reason to the data store. The ACS comprises an application that determines unusual data packet traffic in the enterprise network and transmits a notification comprising information about the unusual data packet traffic and an identity of a host computer associated with the unusual data packet traffic to the data store.
机译:网络威胁减弱系统。该系统包括网络威胁数据存储,多个传感器控制点(SCP)和分析关联系统(ACS),其中至少一个SCP位于企业网络的每个局域网(LAN)段中。每个SCP包括多个传感器应用程序,这些传感器应用程序分析SCP所在的LAN段所传输的数据包,并发送一个标识发送传感器的通知,数据包源的标识,数据目的地的标识数据包,以及向数据存储区发送通知的原因。 ACS包括应用程序,该应用程序确定企业网络中的异常数据包流量,并将包括有关异常数据包流量的信息以及与该异常数据包流量相关联的主机的标识的通知发送到数据存储。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号