发明授权
US07895641B2 Method and system for dynamic network intrusion monitoring, detection and response
有权
动态网络入侵监测,检测和响应的方法和系统
- 专利标题: Method and system for dynamic network intrusion monitoring, detection and response
- 专利标题(中): 动态网络入侵监测,检测和响应的方法和系统
-
申请号: US11551606申请日: 2006-10-20
-
公开(公告)号: US07895641B2公开(公告)日: 2011-02-22
- 发明人: Bruce Schneier , Andrew H. Gross , Jonathan D. Callas
- 申请人: Bruce Schneier , Andrew H. Gross , Jonathan D. Callas
- 申请人地址: US CA Mountain View
- 专利权人: BT Counterpane Internet Security, Inc.
- 当前专利权人: BT Counterpane Internet Security, Inc.
- 当前专利权人地址: US CA Mountain View
- 代理机构: Kilpatrick Townsend & Stockton LLP
- 主分类号: G06F7/04
- IPC分类号: G06F7/04 ; G08B23/00
摘要:
A probe attached to a customer's network collects status data and other audit information from monitored components of the network, looking for footprints or evidence of unauthorized intrusions or attacks. The probe filters and analyzes the collected data to identify potentially security-related events happening on the network. Identified events are transmitted to a human analyst for problem resolution. The analyst has access to a variety of databases (including security intelligence databases containing information about known vulnerabilities of particular network products and characteristics of various hacker tools, and problem resolution databases containing information relevant to possible approaches or solutions) to aid in problem resolution. The analyst may follow a predetermined escalation procedure in the event he or she is unable to resolve the problem without assistance from others. Various customer personnel can be alerted in a variety of ways depending on the nature of the problem and the status of its resolution. Feedback from problem resolution efforts can be used to update the knowledge base available to analysts for future attacks and to update the filtering and analysis capabilities of the probe and other systems.
公开/授权文献
信息查询