首页> 外国专利> Security policy management using incident analysis

Security policy management using incident analysis

机译:使用事件分析进行安全策略管理

摘要

A security analytics system receives incident data (from an incident management system) and security policy information (from a security policy management system). The security analytics system evaluates these data sets against one another, preferably using a rules-based analysis engine. As a result, the security analytics system determines whether a particular security policy configuration (as established by the security policy management system) needs to be (or should be) changed, e.g., to reduce the number of incidents caused by a misconfiguration, to increase its effectiveness in some manner, or the like. As a result of the evaluation, the security analytics system may cause a policy to be updated automatically, notify an administrator of the need for the change (and the recommendation), or take some other action to evolve one or more security policies being enforced by the security policy management system.
机译:安全分析系统(从事件管理系统)接收事件数据和(从安全策略管理系统)接收安全策略信息。安全分析系统最好使用基于规则的分析引擎对这些数据集进行相互评估。结果,安全分析系统确定是否需要(或应该)更改(由安全策略管理系统建立的)特定安全策略配置,例如,以减少由错误配置引起的事件的数量,以增加它以某种方式或类似方式的有效性。评估的结果是,安全分析系统可能会导致策略自动更新,将更改(和建议)的必要性通知管理员,或者采取其他措施来发展由用户实施的一个或多个安全策略。安全策略管理系统。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号