首页> 外国专利> Network monitoring equipment, network monitoring methods, and network monitoring programs

Network monitoring equipment, network monitoring methods, and network monitoring programs

机译:网络监控设备,网络监控方法和网络监控程序

摘要

PROBLEM TO BE SOLVED: To appropriately detect a sign of a cyber attack and appropriately calculate the priority of countermeasures against the detected cyber attack. SOLUTION: In a network monitoring device 100, a CPU 102 detects an increase point of darknet traffic, and the darknet traffic corresponding to the increase point is detected within its own organization, and an observation point and its own organization The correlation score of darknet traffic between them is above the threshold, the source IP address is on the blacklist, it is present as attack information in threat intelligence, there is a log corresponding to the honeypot, and the log is Whether at least one of the following conditions is met: the existing honeypot is in your organization, the CVSS score for the subject is above the threshold, and the vulnerable product is in your organization. Based on the above, the evaluation value indicating the priority of countermeasures against cyber attacks should be calculated. [Selection diagram] Fig. 1
机译:要解决的问题:适当地检测网络攻击的标志,并适当地计算对检测到的网络攻击的对策的优先级。解决方案:在网络监视设备100中,CPU 102检测到Darknet流量的增加点,并且在其自己的组织中检测到与增加点对应的Darknet流量,以及观察点及其自己的组织DarkNet流量的相关分数它们之间的阈值高于阈值,源IP地址位于黑名单上,它作为威胁情报中的攻击信息存在,存在与蜜罐对应的日志,并且日志是满足以下条件中的至少一个情况:现有的蜜罐在您的组织中,主题的CVSS分数高于阈值,易受攻击的产品在您的组织中。基于上述情况,应计算指示反对网络攻击的对策优先考虑的评估值。 [选择图]图1

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号