首页> 外国专利> SYSTEM, METHOD AND COMPUTER READABLE MEDIUM FOR IDENTIFYING MISSING ORGANIZATIONAL SECURITY DETECTION SYSTEM RULES

SYSTEM, METHOD AND COMPUTER READABLE MEDIUM FOR IDENTIFYING MISSING ORGANIZATIONAL SECURITY DETECTION SYSTEM RULES

机译:用于识别缺失的组织安全检测系统规则的系统,方法和计算机可读介质

摘要

A system for identifying missing organizational security detection system rules, the system includes at least one processing circuitry configured to provide a known cyber-attack techniques repository including information of known cyber-attack techniques and required SIEM (or any other organizational security detection system such as EDR, firewall, etc.) rules required for protecting against each of the known cyber-attack techniques, the known rules being in a generic SIEM rules format; obtain existing SIEM rules of a SIEM of an organization, the existing SIEM rules being in a vendor-specific language, other than the generic SIEM rules format; translate the existing SIEM rules to the generic SIEM rules format, using a translation system, giving rise to translated SIEM rules; compare the translated SIEM rules to the required SIEM rules to identify missing rules, being the required SIEM rules not included in the translated SIEM rules.
机译:一种系统识别缺失的组织安全检测系统规则,该系统包括至少一个处理电路,该处理电路被配置为提供一种已知的网络攻击技术存储库,包括已知网络攻击技术的信息和所需的SIEM(或任何其他组织安全检测系统,例如 EDR,防火墙等)保护每个已知的网络攻击技术所需的规则,已知规则处于通用暹粒规则格式; 获取组织的SIEM的现有SIEM规则,现有的SIEM规则以文具特定的语言,除了通用SIEM规则格式之外; 将现有的SIEM规则转换为通用SIEM规则格式,使用翻译系统,推动翻译暹粒规则; 将翻译的SIEM规则与所需的SIEM规则进行比较以识别缺失规则,是未在翻译的SIEM规则中包含所需的SIEM规则。

著录项

  • 公开/公告号EP3876122A1

    专利类型

  • 公开/公告日2021-09-08

    原文格式PDF

  • 申请/专利权人 CYBERPROOF ISRAEL LTD.;

    申请/专利号EP20210158994

  • 发明设计人 ALSHECH ERAN;AMRAM ADAM;

    申请日2021-02-24

  • 分类号G06F21/55;G06F21/57;H04L29/06;

  • 国家 EP

  • 入库时间 2022-08-24 20:54:22

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号