首页> 外国专利> METHOD AND SYSTEM FOR DETECTING INTRUSION IN NETWORKS AND SYSTEMS BASED ON BUSINESS-PROCESS SPECIFICATION

METHOD AND SYSTEM FOR DETECTING INTRUSION IN NETWORKS AND SYSTEMS BASED ON BUSINESS-PROCESS SPECIFICATION

机译:基于业务过程规范的网络入侵检测方法和系统

摘要

Intrusions and incidents on networks and systems are detected using intrusion detection systems. The present invention relates to the field of security in communication networks, control systems and information systems and concerns an intrusion detection system and method based on the specification of business processes and business rules. Different methods are implemented to use events in each system or network as indicators of actions on the systems involved, and these are analyzed to determine whether they correspond to a previously specified business process being run, an alarm being triggered if they do not. The present invention considerably reduces the number of false positives typical in intrusion detection systems, and are particularly useful for protecting systems involved in business processes that can be fully specified, notably industrial systems and systems used in critical infrastructure.
机译:使用入侵检测系统检测网络和系统上的入侵和事件。本发明涉及通信网络,控制系统和信息系统中的安全领域,并且涉及基于业务流程和业务规则的规范的入侵检测系统和方法。实施了不同的方法以将每个系统或网络中的事件用作所涉及的系统上的操作的指示符,并对这些方法进行分析以确定它们是否与正在运行的先前指定的业务流程相对应,如果不符合则触发警报。本发明大大减少了入侵检测系统中典型的误报的数量,并且对于保护涉及可以被完全指定的业务流程的系统,特别是工业系统和关键基础设施中使用的系统特别有用。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号