首页> 外国专利> METHOD AND SYSTEM FOR DETECTING INTRUSION IN NETWORKS AND SYSTEMS BASED ON BUSINESS-PROCESS SPECIFICATION

METHOD AND SYSTEM FOR DETECTING INTRUSION IN NETWORKS AND SYSTEMS BASED ON BUSINESS-PROCESS SPECIFICATION

机译:基于业务过程规范的网络入侵检测方法和系统

摘要

The detection of intrusions or incidents in networks and systems is carried out with the support of Intrusion Detection Systems. The present invention falls within the field of network security, control systems and information systems and refers to a method and a system of IDS based on the specification of the business processes and business rules. Through various methods, the events in each system or network are used as indication of actions on the systems involved, and analyzed to determine if they correspond to the execution of the business process specified in advance, not corresponding an alarm is produced. The present invention significantly reduces the number of typical IDS false positives and has particular application in the protection of systems that participate in business processes that are completely specifiable. Noteworthy are the industrial systems and those used in critical infrastructures.
机译:在入侵检测系统的支持下,对网络和系统中的入侵或事件进行检测。本发明属于网络安全,控制系统和信息系统的领域,并且涉及一种基于业务流程和业务规则的规范的IDS方法和系统。通过各种方法,每个系统或网络中的事件都用作所涉及系统上动作的指示,并进行分析以确定它们是否对应于预先指定的业务流程的执行,而不是对应于产生警报。本发明显着减少了典型的IDS误报的数量,并且在保护参与完全可指定的业务过程的系统中具有特殊的应用。值得注意的是工业系统和关键基础设施中使用的系统。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号