首页> 外国专利> SUPPRESSION OF FALSE ALARMS IN ALARMS ARISING FROM INTRUSION DETECTION PROBES IN A MONITORED INFORMATION SYSTEM

SUPPRESSION OF FALSE ALARMS IN ALARMS ARISING FROM INTRUSION DETECTION PROBES IN A MONITORED INFORMATION SYSTEM

机译:监视信息系统中入侵检测问题引起的虚假警报的抑制

摘要

The invention relates to a system and method for the suppression of false alarms in alarms arising from intrusion detection probes (13a, 13b, 13c) in a monitored information system (1) comprising entities (9, 11a, 11b) producing attacks associated with said alarms and a system for the management of alarms (15), comprising the following steps: -definition, by means of a false alarm suppression module (23), of qualitative relations between the entities (9, 11a, 11b) and a set of profiles; definition, by means of the false alarm suppression module (23), of nominative relations between the set of profiles and a set of names of attacks that the set of profiles is reputed to produce; qualification, by means of the false alarm suppression module (23),of an alarm given by a false alarm if the entity (9, 11a, 11b) involved in the given alarm has a profile which is reputed to produce the attack associated with said given alert.
机译:本发明涉及一种用于抑制监视信息系统(1)中由入侵检测探测器(13a,13b,13c)引起的警报中的虚假警报的系统和方法,该系统包括产生与所述攻击相关联的攻击的实体(9、11a,11b)。警报和警报管理系统(15),包括以下步骤:-通过错误警报抑制模块(23)定义实体(9、11a,11b)与一组警报之间的定性关系个人资料;借助于误报抑制模块(23),定义该组简档与该组简档所产生的攻击名称集之间的名义关系;如果涉及给定警报的实体(9、11a,11b)具有据称产生与所述警报相关联的攻击的特征,则通过虚假警报抑制模块(23)对由虚假警报给出的警报进行限定。给警报。

著录项

  • 公开/公告号EP1751957A1

    专利类型

  • 公开/公告日2007-02-14

    原文格式PDF

  • 申请/专利权人 FRANCE TELECOM;

    申请/专利号EP20050769457

  • 发明设计人 DEBAR HERVE;MORIN BENJAMIN;

    申请日2005-05-09

  • 分类号H04L29/06;G06F1/00;

  • 国家 EP

  • 入库时间 2022-08-21 20:46:46

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号