发明申请
US20080229421A1 Adaptive data collection for root-cause analysis and intrusion detection
有权
根本原因分析和入侵检测的自适应数据收集
- 专利标题: Adaptive data collection for root-cause analysis and intrusion detection
- 专利标题(中): 根本原因分析和入侵检测的自适应数据收集
-
申请号: US11717978申请日: 2007-03-14
-
公开(公告)号: US20080229421A1公开(公告)日: 2008-09-18
- 发明人: Efim Hudis , Yair Helman , Joseph Malka , Uri Barash
- 申请人: Efim Hudis , Yair Helman , Joseph Malka , Uri Barash
- 申请人地址: US WA Redmond
- 专利权人: Microsoft Corporation
- 当前专利权人: Microsoft Corporation
- 当前专利权人地址: US WA Redmond
- 主分类号: G06F11/00
- IPC分类号: G06F11/00
摘要:
Endpoints in an enterprise security environment are configured to adaptively switch from their normal data collection mode to a long-term, detailed data collection mode where advanced analyses are applied to the collected detailed data. Such adaptive data collection and analysis is triggered upon the receipt of a security assessment of a particular type, where a security assessment is defined as a tentative assignment by an endpoint of broader contextual meaning to information (i.e., data in some context) that is collected about an object of interest. A specialized endpoint is coupled to the security assessment channel and performs as a centralized audit point by subscribing to all security assessments, logging the security assessments, and also logging the local actions taken by endpoints in response to detected security incidents in the environment. The specialized endpoint is arranged to perform various analyses and processes on historical security assessments.
公开/授权文献
信息查询