- 专利标题: Method and system for verifying validity of detection result
-
申请号: US16403994申请日: 2019-05-06
-
公开(公告)号: US11956264B2公开(公告)日: 2024-04-09
- 发明人: Juho Yun , Seongho Ka
- 申请人: LINE Corporation
- 申请人地址: JP Tokyo
- 专利权人: LINE CORPORATION
- 当前专利权人: LINE CORPORATION
- 当前专利权人地址: JP Tokyo
- 代理机构: Harness, Dickey & Pierce, P.L.C.
- 主分类号: H04L29/06
- IPC分类号: H04L29/06 ; H04L9/40 ; H04L69/00
摘要:
A validity verification method may include receiving an event to be analyzed from a security information & event management (SIEM) server, the event to be analyzed selected by the SIEM server from a plurality of events detected by different security devices based on a desired correlation rule; registering the event to be analyzed; collecting raw data associated with the registered event from a security device corresponding to the registered event among the different security devices; acquiring location information of an intended network location associated with an attack based on the collected raw data; determining a validity status of the registered event based on the acquired location information; generating an exceptional processing message of the registered event; and transmitting the generated exceptional processing message to the SIEM server based on results of the determining the validity status of the registered event.
公开/授权文献
信息查询