首页> 外国专利> Method and system for detecting intrusion into and misuse of a data processing system

Method and system for detecting intrusion into and misuse of a data processing system

机译:用于检测对数据处理系统的入侵和滥用的方法和系统

摘要

Disclosed is a Security Indications and Warning (SI&W) Engine usable in conjunction with an audit agent. The audit agent forwards normalized audits to the SI&W Engine. The SI&W Engine groups the normalized audits into related groupings. Gauges are used to count the number of occurrences of audited events. A statistical engine provides statistical representations of the number of events per user, per session and per node. A predetermined number of criteria are defined a particular gauge or gauge pair. There may be many criteria for a particular network. When a predetermined number of criteria within a criteria set are triggered, an indicator is triggered. More complex indicators can use combinations of lower level indicators to provide further indications of potential security threads. Thus, a hierarchical system of gauges, criteria and indicators is used to measure boundary violations and breaches of different barriers. Advantageously, because there are no predefined scenarios or profiles that must be performed by a potential misuser or intruder, the SI&W Engine of the present invention is capable of indicating that a potential security threat exists in near-real time.
机译:公开了一种可与审计代理一起使用的安全指示和警告(SI&W)引擎。审核代理将规范化审核转发到SI&W Engine。 SI&W Engine将标准化审核分组为相关分组。量表用于计算已审核事件的发生次数。统计引擎提供每个用户,每个会话和每个节点的事件数量的统计表示。特定量规或量规对定义了预定数量的标准。特定网络可能有很多标准。当触发标准集中的预定数量的标准时,触发指示器。更复杂的指示符可以使用较低级别的指示符的组合来提供潜在安全线程的进一步指示。因此,使用量表,标准和指标的分层系统来度量边界违规和不同障碍的突破。有利地,因为没有潜在的滥用者或入侵者必须执行的预定义场景或简档,所以本发明的SI&W引擎能够指示接近实时的潜在安全威胁。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号