首页> 外国专利> Testing security incident response through automated injection of known indicators of compromise

Testing security incident response through automated injection of known indicators of compromise

机译:通过自动注入已知的危害指标来测试安全事件响应

摘要

Disclosed are various embodiments for testing the security incident response of an organization through automated injection of a known indicator of compromise. A stream of event data generated by a network monitoring system of an organization is received. The stream of event data is modified to include data embodying a fabricated indicator of compromise. The stream of event data that has been modified is then provided to an intrusion detection system of the organization. Metrics are then generated that assess the response of the organization to the fabricated indicator of compromise.
机译:公开了用于通过自动注入已知的危害指示器来测试组织的安全事件响应的各种实施例。接收由组织的网络监视系统生成的事件数据流。事件数据流被修改为包括体现妥协的伪造指标的数据。然后将已修改的事件数据流提供给组织的入侵检测系统。然后生成度量,以评估组织对妥协的伪造指标的响应。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号