首页> 外国专利> A method for intrusion detection rate with audit correlation

A method for intrusion detection rate with audit correlation

机译:一种具有审计相关性的入侵检测率方法

摘要

PURPOSE: A method for improving intrusion detection through a relationship algorithm of a audit log is provided to improve the intrusion detection and lower wrong detection through the relationship of three audit logs having a different property. CONSTITUTION: A system log(2), a packet log(3), and a system call log(4) of a login module(1) generate an intrusion detecting pattern(6) through a audit log parser(5), and judge the intrusion through the intrusion detector(7). The intrusion of the audit log is detected through the intrusion detector in real-time. In case that the intrusion is detected, an intrusion confronting/reporting module(8) is operated.
机译:目的:提供一种通过审计日志的关系算法改善入侵检测的方法,以通过具有不同属性的三个审计日志之间的关系来改善入侵检测并减少错误检测。组成:登录模块(1)的系统日志(2),数据包日志(3)和系统调用日志(4)通过审核日志解析器(5)生成入侵检测模式(6),并进行判断通过入侵检测器(7)入侵。审核日志的入侵是通过入侵检测器实时检测到的。在检测到入侵的情况下,操作入侵面对/报告模块(8)。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号