首页> 外国专利> MULTIPHASE THREAT ANALYSIS AND CORRELATION ENGINE

MULTIPHASE THREAT ANALYSIS AND CORRELATION ENGINE

机译:多相威胁分析和相关引擎

摘要

Provided are systems, methods, and computer-program products for a targeted threat intelligence engine, implemented in a network device. The network device may receive incident data, which may include information derived starting at detection of an attack on the network until detection of an event. The network device may include analytic engines that run in a predetermined order. An analytic engine can analyze incident data of a certain data type, and can produce a result indicating whether a piece of data is associated with the attack. The network device may produce a report of the attack, which may include correlating the results from the analytic engines. The report may provide information about a sequence of events that occurred in the course of the attack. The network device may use the record of the attack to generate indicators, which may describe the attack, and may facilitate configuring security for a network.
机译:提供在网络设备中实现的针对目标威胁情报引擎的系统,方法和计算机程序产品。网络设备可以接收事件数据,事件数据可以包括从检测到网络攻击开始直到检测到事件而得出的信息。该网络设备可以包括以预定顺序运行的分析引擎。分析引擎可以分析某种数据类型的事件数据,并可以产生指示某条数据是否与攻击有关的结果。网络设备可能会生成攻击报告,其中可能包括关联来自分析引擎的结果。该报告可以提供有关在攻击过程中发生的一系列事件的信息。网络设备可以使用攻击的记录来生成指示符,该指示符可以描述攻击,并且可以有助于配置网络的安全性。

著录项

  • 公开/公告号US2017223046A1

    专利类型

  • 公开/公告日2017-08-03

    原文格式PDF

  • 申请/专利权人 ACALVIO TECHNOLOGIES INC.;

    申请/专利号US201715404693

  • 发明设计人 ABHISHEK SINGH;

    申请日2017-01-12

  • 分类号H04L29/06;

  • 国家 US

  • 入库时间 2022-08-21 13:49:12

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号