首页> 外国专利> Monitoring operational activities in networks and detecting potential network intrusions and misuses

Monitoring operational activities in networks and detecting potential network intrusions and misuses

机译:监视网络中的运营活动并检测潜在的网络入侵和滥用

摘要

Concepts and technologies disclosed herein are for monitoring operational activities in networks and detecting potential network intrusions and misuses. According to one aspect disclosed herein, an intrusion detection system can collect logs from an authentication, authorization, and accounting system. The intrusion detection system can extract information from the logs, update intrusion detection information utilized by an intrusion detection rule based upon the information extracted from the logs, update a profile utilized by the intrusion detection rule, compare the profile and the intrusion detection rule against a running state of an on-going session, tag corresponding log entries with a threat score, calculate the threat scores from the corresponding log entries to create an aggregated threat score, and present the aggregated threat score. The intrusion detection system can also present an alarm if the aggregated threat score triggers an alarm condition.
机译:本文公开的概念和技术用于监视网络中的操作活动并检测潜在的网络入侵和滥用。根据本文公开的一个方面,入侵检测系统可以从认证,授权和计费系统收集日志。入侵检测系统可以从日志中提取信息,基于从日志中提取的信息来更新入侵检测规则所使用的入侵检测信息,更新入侵检测规则所使用的配置文件,然后将配置文件和入侵检测规则与正在进行的会话的运行状态,用威胁评分标记相应的日志条目,从相应的日志条目计算威胁评分以创建汇总的威胁评分,并显示汇总的威胁评分。如果汇总的威胁评分触发了警报状况,则入侵检测系统还可以发出警报。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号