首页>
外国专利>
Intrusion detection report correlator and analyzer
Intrusion detection report correlator and analyzer
展开▼
机译:入侵检测报告相关器和分析器
展开▼
页面导航
摘要
著录项
相似文献
摘要
A computer/computer network security alert management system aggregates information from multiple intrusion detectors. Utilizing reports from multiple intrusion detectors reduces the high false alarm rate experienced by individual detectors while also improving detection of coordinated attacks involving a series of seemingly harmless operations. An internal representation of a protected enclave is utilized, and intrusion detection system (IDS) information is correlated to accurately prioritize alerts. In one embodiment, the system is capable of utilizing data from most existing IDS products, with flexibility to add further IDS products.
展开▼