首页> 外国专利> Detection of advanced persistent threat attack on a private computer network

Detection of advanced persistent threat attack on a private computer network

机译:检测专用计算机网络上的高级持续威胁攻击

摘要

A system for detecting an advanced persistent threat (APT) attack on a private computer network includes hosts computers that receive network traffic and process the network traffic to identify an access event that indicates access to a critical asset of an organization that owns or maintains the private computer network. The critical asset may be a computer that stores confidential data of the organization. Access events may be stored in an event log as event data. Access events indicated in the event log may be correlated using a set of alert rules to identify an APT attack.
机译:一种用于检测专用计算机网络上的高级持久威胁(APT)攻击的系统,包括主机计算机,这些主机接收网络流量并处理网络流量,以识别访问事件,该访问事件指示对拥有或维护该私有设备的组织的重要资产的访问计算机网络。关键资产可以是存储组织机密数据的计算机。访问事件可以作为事件数据存储在事件日志中。可以使用一组警报规则来关联事件日志中指示的访问事件,以识别APT攻击。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号