首页> 外国专利> SYSTEM AND METHOD OF PROCESSING INFORMATION SECURITY EVENTS TO DETECT CYBERATTACKS

SYSTEM AND METHOD OF PROCESSING INFORMATION SECURITY EVENTS TO DETECT CYBERATTACKS

机译:处理信息安全事件以检测网络内的系统和方法

摘要

A method for processing information security events of a computer system includes receiving information related to a plurality of information security events occurred in the computer system. Each of the events includes an event related to a possible violation of information security of the computer system. A verdict is determined for each of the events. The verdict includes: i) information security incident or ii) false positive. The verdict is false positive if the probability of a false positive for the corresponding event is greater than a first threshold. Verdicts are changed for a subset of the events from the false positive to the information security incident. A number of events in the subset is lower than a second threshold. An analysis of the events having a verdict of the information security incident is performed to determine if the computer system is under a cyberattack.
机译:用于处理计算机系统的信息安全事件的方法包括接收与计算机系统中发生的多个信息安全事件相关的信息。 每个事件包括与可能违反计算机系统信息安全性相关的事件。 针对每个事件确定判决。 判决包括:i)信息安全事件或II)假阳性。 如果相应事件的假阳性的概率大于第一阈值,则判决是假阳性的。 从错误正向信息安全事件的错误阳性将事件的子集更改判决。 子集中的许多事件低于第二个阈值。 执行对具有信息安全事件的判决的事件的分析,以确定计算机系统是否位于网络内部。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号