首页> 外国专利> SYSTEMS AND METHODS OF INFORMATION SECURITY MONITORING WITH THIRD-PARTY INDICATORS OF COMPROMISE

SYSTEMS AND METHODS OF INFORMATION SECURITY MONITORING WITH THIRD-PARTY INDICATORS OF COMPROMISE

机译:信息安全监测系统和方法,第三方指标妥协指标

摘要

An information security monitoring system can import indicators of compromise (IOC) definitions in disparate formats from third-party source systems, convert them into editable security definitions in an internal system format, and provide a user interface for composing or editing these security definitions with enhancements, including complex security definitions such as those having a nested Boolean structure and/or those that reference one or more security definitions, a behavioral rule, and/or a vulnerability description. One or more whitelists can be added to handle exceptions. Each composed or modified security definition is then compiled into an executable rule. The executable rule, when evaluated, produces a result indicative of an endpoint security action needed in view of an endpoint event that meets the composed or modified security definition.
机译:信息安全监控系统可以从第三方源系统中以不同格式导入妥协(IoC)定义的指标,以内部系统格式将它们转换为可编辑的安全定义,并为用户界面提供用于编写​​或编辑这些安全定义的增强功能,包括复杂的安全定义,例如具有嵌套布尔结构的那些和/或引用一个或多个安全定义,行为规则和/或漏洞描述的安全定义。可以添加一个或多个白名单以处理异常。然后将每个组成或修改的安全性定义编译为可执行规则。鉴于符合组成或修改的安全定义的端点事件,可执行规则生成指示所需的结果。

著录项

  • 公开/公告号US2021144178A1

    专利类型

  • 公开/公告日2021-05-13

    原文格式PDF

  • 申请/专利权人 OPEN TEXT HOLDINGS INC.;

    申请/专利号US201916678813

  • 发明设计人 MICHAEL JAMES BAILEY;

    申请日2019-11-08

  • 分类号H04L29/06;

  • 国家 US

  • 入库时间 2022-08-24 18:40:00

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号