发明授权
- 专利标题: Intrusion detection system alerts mechanism
- 专利标题(中): 入侵检测系统警报机制
-
申请号: US13100709申请日: 2011-05-04
-
公开(公告)号: US08103612B2公开(公告)日: 2012-01-24
- 发明人: Mian Zhou , Sean Kenric Catlett
- 申请人: Mian Zhou , Sean Kenric Catlett
- 申请人地址: US NC Charlotte
- 专利权人: Bank of America Corporation
- 当前专利权人: Bank of America Corporation
- 当前专利权人地址: US NC Charlotte
- 代理机构: Banner & Witcoff, Ltd.
- 代理商 Michael A. Springs
- 主分类号: G06F17/00
- IPC分类号: G06F17/00 ; G06N5/02
摘要:
A system and method for analyzing Intrusion Detection System (IDS) alert data associated with a computer network is described. The method includes applying first association rules to obtained IDS alert data associated with a computer network and processing the obtained IDS alert data with the first association rules. Analyst feedback data associated with the processed obtained IDS alert data is received, and a training data set from the analyst feedback data is received. New association rules are determined based upon the training data set, and the new association rules are outputted to a display of a computing device. Outputting the new association rules may include outputting patterns within the IDS alert data of false positive alerts. The new association rules may be applied back to the obtained IDS alert data.
公开/授权文献
- US20110208677A1 INTRUSION DETECTION SYSTEM ALERTS MECHANISM 公开/授权日:2011-08-25
信息查询