首页> 外国专利> CONTEXT-AWARE NETWORK FORENSICS

CONTEXT-AWARE NETWORK FORENSICS

机译:上下文感知网络取证

摘要

A system and method for managing a security event and its associated forensic context are disclosed. Network forensics monitors and analyzes data flows in the network to help security analysts review, analyze and eliminate security threats. Security threats in a network environment are generally detected by one or more devices on the network. If a security threat is determined to be serious or sufficiently significant, security events corresponding to security threats are frequently generated and stored in the system. To assist in further review and analysis of security threats, timely and relevant contextual information about network security events can be acquired and generated with each security event. The forensic context can access the security manager to view security events and provide detailed information about the environment around the security events.
机译:公开了用于管理安全事件及其关联的取证上下文的系统和方法。网络取证监视和分析网络中的数据流,以帮助安全分析人员查看,分析和消除安全威胁。网络环境中的安全威胁通常由网络上的一个或多个设备检测到。如果确定安全威胁是严重的或足够重要,则经常生成与安全威胁相对应的安全事件并将其存储在系统中。为了帮助进一步检查和分析安全威胁,可以与每个安全事件一起获取并生成有关网络安全事件的及时且相关的上下文信息。法证上下文可以访问安全管理器以查看安全事件,并提供有关安全事件周围环境的详细信息。

著录项

  • 公开/公告号KR101836016B1

    专利类型

  • 公开/公告日2018-03-07

    原文格式PDF

  • 申请/专利权人 맥아피 엘엘씨;

    申请/专利号KR20167009010

  • 申请日2013-11-06

  • 分类号H04L29/06;

  • 国家 KR

  • 入库时间 2022-08-21 12:38:16

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号