首页> 外国专利> Method and system for analysis of security events in a managed computer network

Method and system for analysis of security events in a managed computer network

机译:用于分析托管计算机网络中的安全事件的方法和系统

摘要

An event retrieval and analysis system compares counts of event data for a device to stored profile counts to determine if alerts should be triggered. Event data can be retrieved by a sensor. Rules for analyzing the event data can be retrieved based on the device. The event data is analyzed based on the rules to determine recordable events. Recordable events are organized into categories representing a type or severity of attack. Current event counts are calculated by summing the recordable events for each category. A normal profile is retrieved for the device and compared to the current event count. A percentage change trigger can be retrieved from a threshold matrix based on the current event count. The percentage increase of the current event count over the normal profile is calculated and compared to the percentage change trigger to determine if an alert is triggered by the analysis system.
机译:事件检索和分析系统将设备的事件数据计数与存储的配置文件计数进行比较,以确定是否应触发警报。事件数据可以由传感器检索。可以基于设备检索分析事件数据的规则。根据规则分析事件数据,以确定可记录的事件。可记录的事件分为代表攻击类型或严重性的类别。当前事件计数是通过将每个类别的可记录事件相加得出的。检索设备的常规配置文件,并将其与当前事件计数进行比较。可以基于当前事件计数从阈值矩阵中检索百分比变化触发。计算当前事件计数在正常配置文件上的增加百分比,并将其与百分比更改触发器进行比较,以确定分析系统是否触发了警报。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号