首页> 外国专利> SYSTEMS AND METHODS FOR FORENSIC ANALYSIS OF NETWORK BEHAVIOR

SYSTEMS AND METHODS FOR FORENSIC ANALYSIS OF NETWORK BEHAVIOR

机译:网络行为取证分析的系统和方法

摘要

Systems and methods monitor and manage computer network traffic and identify a status of normality or consistency of the traffic on a per user, per internet protocol address or MAC address basis. More specifically, the systems and methods determine, with degrees of significance, the abnormality or inconsistency of network traffic from a user, IP address or MAC address based on a comparison of said network traffic to previous network traffic from the same location. Moreover, the systems and methods monitor and manage the network traffic whereby, after an anomaly has occurred, network traffic is tagged as suspicious and thereafter is flagged for forensic study and placed in storage. In addition, the systems and methods report tagged traffic and alert administrators of a breach or violation in the computer network.
机译:系统和方法监视和管理计算机网络流量,并基于每个用户,每个互联网协议地址或MAC地址识别流量的正常状态或一致性。更具体地,所述系统和方法基于所述网络流量与来自相同位置的先前网络流量的比较,以有意义的程度确定来自用户,IP地址或MAC地址的网络流量的异常或不一致。此外,该系统和方法监视和管理网络流量,从而在异常发生之后,将网络流量标记为可疑,然后标记以进行法医研究并将其存储。另外,这些系统和方法报告标记的流量,并向管理员警告计算机网络中的违规行为。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号