发明授权
- 专利标题: Network security monitoring system
- 专利标题(中): 网络安全监控系统
-
申请号: US10443946申请日: 2003-05-21
-
公开(公告)号: US07483972B2公开(公告)日: 2009-01-27
- 发明人: Partha Bhattacharya , Jan Christian Lawrence
- 申请人: Partha Bhattacharya , Jan Christian Lawrence
- 申请人地址: US CA San Jose
- 专利权人: Cisco Technology, Inc.
- 当前专利权人: Cisco Technology, Inc.
- 当前专利权人地址: US CA San Jose
- 代理机构: Hickman Palermo Truong & Becker LLP
- 主分类号: G06F15/177
- IPC分类号: G06F15/177 ; G06F11/00
摘要:
A security monitoring system processes event messages related to computer network security in real time, evaluating inter-event constraints so as to identify combinations of events that are partial solutions to a predefined event correlation rule, and furthermore evaluating combinations of the partial solutions do determine if they together satisfy the predefined event correlation rule. A decision tree is formed based on the rule. Event messages are categorized into groups at leaf nodes of the tree in accordance with a plurality of intra-event constraints, and then the messages are correlated in accordance with a plurality of inter-event constraints at non-leaf nodes of the tree. When the inter-event constraint at a root node of the tree has been satisfied, a network attack alert is issued and protective actions may be taken.
公开/授权文献
- US20040133672A1 Network security monitoring system 公开/授权日:2004-07-08
信息查询