首页> 外国专利> Procedure for the Association of Heterogeneous Data Sources for Security of communication networks and associated System

Procedure for the Association of Heterogeneous Data Sources for Security of communication networks and associated System

机译:通信网络和相关系统安全性的异构数据源关联程序

摘要

Association procedure (100) of a First Data source with a Second Data Source.The First Data Source (4) constitutes a table generated by a Monitoring Component (3) of a Communication Network (2),Each row of the table corresponds to an event (and _ (i) in the network that meets a predefined Alert rule.The Second Data Source (6) is formed by a Plurality of binary files (m, F _)Each file is generated by a Probe (3) analysis of the contents of intercepted packets in the Network.A file that collects The Data packets that belong to a same Communication session in such a Network, the method comprises the steps of: - providing a class,Warning "class, defined by a Plurality of variablesA function of Building Codes and a function of checking Equality; - For Each event (and _ (i) of the First Data Source (4),ALERT (_ instantiating an object of the class i) Alert and update a Table of arbitrary Choice (14) by calculating the value of the building function for that object code Verification ALERTa instantiated for each file; (F _ m) the second source of Data (6),Analyze the file to extract the possible values for the variables of the class warning; use function of Building Codes and checking the function of equal Class warningVerify, by means of the arbitrary Choice (Table 14), if the extracted values correspond to an object instantiated warning; and, if so,Associate a file identifier in memory of that object is instantiated for Alert,According to the function of creating codes to check the warning class is defined by: * * * * formula where n is the number of bytes used to represent an object of Class warningAnd sq is a Weight that allows to weigh the fifth byte.
机译:第一数据源与第二数据源的关联过程(100)。第一数据源(4)构成由通信网络(2)的监视组件(3)生成的表,该表的每一行对应于一个事件(和_(i)在网络中满足预定义的警报规则。第二个数据源(6)由多个二进制文件(m,F _)组成。每个文件由Probe(3)对收集属于此类网络中相同通信会话的数据包的文件的文件,该方法包括以下步骤:-提供一个类别为“警告”的类别,该类别由多个变量建筑法规的功能和检查相等性的功能;-对于每个事件(以及第一个数据源(4)的_(i),ALERT(_实例化类i的对象)警报并更新任意选择表(14)通过计算该目标代码的建筑函数的值来验证ALERTa i为每个文件实例化; (F_m)数据的第二个来源(6),分析文件以提取类警告变量的可能值;使用建筑规范的功能并检查相等级别的警告的功能,通过任意选择(表14)来验证是否所提取的值对应于对象实例化警告;如果是,则为该对象实例化该对象的内存中的文件标识符的关联,根据创建代码来检查警告类别的功能由以下公式定义:* * * *公式其中n是用于表示的字节数警告类的对象sq是一个权重,可以权衡第五个字节。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号