首页> 外国专利> USING BEHAVIOR-BASED ANALYSIS TECHNIQUES FOR ADVANCED PERSISTENT THREAT ATTACK DETECTION AND RESPONSE, SYSTEM AND METHOD FOR THEREOF

USING BEHAVIOR-BASED ANALYSIS TECHNIQUES FOR ADVANCED PERSISTENT THREAT ATTACK DETECTION AND RESPONSE, SYSTEM AND METHOD FOR THEREOF

机译:使用基于行为的分析技术进行高级持久威胁攻击检测和响应,其系统和方法

摘要

An intelligent persistent attack detection and response system by using a behavior-based analysis technology according to one embodiment of the present invention comprises: a function audit module for managing an operation of entire module and for supporting an audit thereof; an audit policy module for defining a target scope of auditing of system state and for managing a standard policy for determining a validity of an attack; a system state audit module for retrieving the target scope of auditing as defined in the audit policy module and for performing an audit on a state of audit target and determining, upon detection of an audit violation act, a validity of the attack and for analyzing an attack type thereof and a scope of damage; and an audit violation response module for receiving a result of the attack analysis from the system state audit module and for deriving response measures corresponding to the attack and for executing the response measures.
机译:根据本发明一个实施例的利用基于行为的分析技术的智能持久攻击检测和响应系统包括:功能审计模块,用于管理整个模块的操作并支持对其进行审计;审核策略模块,用于定义系统状态审核的目标范围以及管理用于确定攻击有效性的标准策略;系统状态审核模块,用于检索审核策略模块中定义的审核目标范围,并针对审核目标的状态执行审核,并在检测到审核违规行为时确定攻击的有效性,并分析其攻击类型和损害范围;审计违规响应模块,用于从系统状态审计模块接收攻击分析的结果,并导出与攻击对应的响应措施,并执行响应措施。

著录项

  • 公开/公告号KR20150078972A

    专利类型

  • 公开/公告日2015-07-08

    原文格式PDF

  • 申请/专利权人 WINS TECHNET CO. LTD.;

    申请/专利号KR20130168870

  • 发明设计人 GHI JUNG HO;KIM DONG CHUN;

    申请日2013-12-31

  • 分类号G06F21/55;

  • 国家 KR

  • 入库时间 2022-08-21 14:59:40

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号