首页> 外国专利> Method for adapting security policies of an information system infrastructure

Method for adapting security policies of an information system infrastructure

机译:适应信息系统基础设施安全策略的方法

摘要

The present invention refers to a method for adapting security policies of an information system infrastructure in function of attacks wherein it comprises the steps of: - storing potential attacks and their associated risks in a data repository (125); - storing curative security policies (128) in response of the potential attacks in a data repository; - monitoring (101) entering contents representing data streams of the information system; - detecting (129) at least one attack in the information system; - assessing a success probability parameter (132) of the at least one detected attack and its associated cost impact parameter (133); - assessing an activation impact parameter (136) of at least one curative security policy in response to the at least one detected attack and its associated cost impact parameter; - deciding of the activation or deactivation (134) of a curative security policy in function of the success probability parameter of the, at least one, detected attack, of the activation impact parameter of at least one curative security policy and of the cost impact parameters of both the detected at least one attack and the at least one curative security policy.
机译:本发明涉及一种用于根据攻击来调整信息系统基础设施的安全策略的方法,其中包括以下步骤:-将潜在的攻击及其相关风险存储在数据库中(125);响应于数据库中的潜在攻击,存储有效的安全策略(128);-监视(101)输入表示信息系统的数据流的内容;-检测(129)信息系统中的至少一种攻击;-评估至少一个检测到的攻击的成功概率参数(132)及其相关的成本影响参数(133);-响应于检测到的至少一种攻击及其相关的成本影响参数,评估至少一种治疗性安全策略的激活影响参数(136);-根据至少一个检测到的攻击的成功概率参数,至少一种治愈性安全策略的激活影响参数和成本影响参数,决定治愈性安全策略的激活或停用(134)检测到的至少一种攻击和至少一种有效的安全策略。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号