首页> 外国专利> Intrusion detection report correlator and analyzer

Intrusion detection report correlator and analyzer

机译:入侵检测报告相关器和分析器

摘要

A computer/computer network security alert management system aggregates information from multiple intrusion detectors. Utilizing reports from multiple intrusion detectors reduces the high false alarm rate experienced by individual detectors while also improving detection of coordinated attacks involving a series of seemingly harmless operations. An internal representation of a protected enclave is utilized, and intrusion detection system (IDS) information is correlated to accurately prioritize alerts. In one embodiment, the system is capable of utilizing data from most existing IDS products, with flexibility to add further IDS products.
机译:计算机/计算机网络安全警报管理系统聚集来自多个入侵检测器的信息。利用来自多个入侵检测器的报告,可以降低单个检测器所遭受的高误报率,同时还可以改善对涉及一系列看似无害的操作的协同攻击的检测。利用受保护区域的内部表示,并关联入侵检测系统(IDS)信息以准确确定警报的优先级。在一个实施例中,该系统能够利用来自大多数现有IDS产品的数据,并具有添加更多IDS产品的灵活性。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号