首页> 外国专利> Method and system for reducing the volume of audit data and normalizing the audit data received from heterogeneous sources

Method and system for reducing the volume of audit data and normalizing the audit data received from heterogeneous sources

机译:减少审计数据量并使来自异构源的审计数据规范化的方法和系统

摘要

A method of reducing the volume of native audit data from further analysis by a misuse and intrusion detection engine is disclosed. Typically, more than ninety percent of the volume of audit information received from heterogeneous operating systems does not need to be analyzed by a misuse and intrusion detection engine because this audit information can be filtered out as not posing a security threat. Advantageously, by reducing (eliminating) the volume of audit information, a misuse and intrusion engine can more quickly determine whether a security threat exists because the volume of data that the engine must consider is drastically reduced. Also, advantageously, the audit information that is forwarded to the engine is normalized to a standard format, thereby reducing the computational requirements of the engine. The method of reducing the volume of native audit data includes comparing each of the native audits against at least one template and against at least one native audit. By matching the native audits against templates of native audits that do not pose security threats, the native audits that do not pose security threats can be reduced out from further consideration. The native audits that are determined to pose potential security threats are transformed into a standardized format for further analysis by a misuse and intrusion detection engine.
机译:公开了一种通过滥用和入侵检测引擎来减少来自进一步分析的本地审核数据量的方法。通常,不需要使用滥用和入侵检测引擎来分析从异构操作系统接收的审核信息量的百分之九十以上,因为可以过滤掉该审核信息,因为这不会构成安全威胁。有利地,通过减少(消除)审核信息的数量,滥用和入侵引擎可以更快地确定是否存在安全威胁,因为该引擎必须考虑的数据量已大大减少。同样,有利地,转发给引擎的审核信息被标准化为标准格式,从而减少了引擎的计算需求。减少本地审计数据量的方法包括将每个本地审计与至少一个模板和至少一个本地审计进行比较。通过将本机审核与不构成安全威胁的本机审核模板进行匹配,可以减少不构成安全威胁的本机审核。确定为构成潜在安全威胁的本机审核将转换为标准化格式,以供滥用和入侵检测引擎进一步分析。

著录项

  • 公开/公告号AU4411999A

    专利类型

  • 公开/公告日2000-01-24

    原文格式PDF

  • 申请/专利权人 PRC INC.;

    申请/专利号AU19990044119

  • 发明设计人 JEFFREY H. WALKER;

    申请日1999-06-02

  • 分类号G06F1/00;

  • 国家 AU

  • 入库时间 2022-08-22 01:51:42

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号