首页> 外国专利> Automatic categorization of IDPS signatures from multiple different IDPS systems

Automatic categorization of IDPS signatures from multiple different IDPS systems

机译:多个不同IDPS系统自动分类IDPS签名

摘要

Unknown and reference signatures are accessed. The unknown and reference signatures indicate patterns that correspond to known threats to resources (such as computer systems and/or computer networks) in a computer environment and comprise a multitude of descriptive elements having information describing different aspects of a corresponding signature. A set of similarity measures is created of the unknown and reference signatures from different perspectives, each perspective corresponding to a descriptive element. The set of similarity measures are integrated to generate an overall similarity metric. The overall similarity metric is used to find appropriate categories in the reference signatures into which the unknown signatures should be placed. The unknown signatures are placed into the appropriate categories to create a mapping from the unknown signatures to the reference signatures. The mapping is output for use by an IDPS for determining whether a threat has occurred to the resources in the computer environment.
机译:访问未知和参考签名。未知和参考签名指示与计算机环境中的资源(例如计算机系统和/或计算机网络)的已知威胁对应的模式,并且包括具有描述相应签名的不同方面的信息的多个描述性元件。从不同的角度来创建一组相似度测量,从不同的角度来看,对应于描述元素的每个透视。集成了相似度量的集合以生成整体相似度量。整体相似性度量标准用于在附图标记中找到适当的类别,其中应放置未知签名。未知的签名被放入适当的类别中,以从未知签名到引用签名的映射。输出映射以用于IDPS用于确定计算机环境中资源是否发生了威胁。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号