Computer-implemented method and system for security event correlation
    12.
    发明授权
    Computer-implemented method and system for security event correlation 有权
    计算机实现的安全事件相关方法和系统

    公开(公告)号:US07673335B1

    公开(公告)日:2010-03-02

    申请号:US10975374

    申请日:2004-10-29

    IPC分类号: G06F12/14

    CPC分类号: G06F21/554 G06F21/552

    摘要: A system and method for analyzing events from devices relating to network security, includes a device interface(s), for receiving events from devices. One or more processors, responsive to the event received pursuant to the device interfaces, evaluate the event in accordance with rules, wherein the rules define, inter alia, an operation the system is to take to evaluate the event and an action to be taken under specified conditions. Also, the processor can determine, responsive to the received event, whether the event is of interest, and if not, discarding the event. The processor can provide a correlation corresponding to the at least one event, for the rules.

    摘要翻译: 用于分析与网络安全有关的设备的事件的系统和方法包括用于从设备接收事件的设备接口。 响应于根据设备接口接收到的事件的一个或多个处理器根据规则来评估事件,其中规则除其他外定义系统要采取的操作以评估事件和要采取的行动 指定条件。 此外,处理器可以响应于所接收的事件来确定事件是否是感兴趣的,如果不是,则丢弃该事件。 对于规则,处理器可以提供对应于至少一个事件的相关性。

    SYSTEM AND METHOD FOR DISCOVERY ENRICHMENT IN AN INTELLIGENT WORKLOAD MANAGEMENT SYSTEM
    15.
    发明申请
    SYSTEM AND METHOD FOR DISCOVERY ENRICHMENT IN AN INTELLIGENT WORKLOAD MANAGEMENT SYSTEM 失效
    智能工作负载管理系统中发现丰富的系统与方法

    公开(公告)号:US20110126275A1

    公开(公告)日:2011-05-26

    申请号:US12762015

    申请日:2010-04-16

    IPC分类号: H04L9/32 G06F21/00 G06F17/30

    摘要: The system and method described herein for discovery enrichment in an intelligent workload management system may include a computing environment having a model-driven, service-oriented architecture for creating collaborative threads to manage workloads. In particular, the management threads may converge information for managing identities and access credentials, which may provide information that can enrich discovery of physical and virtual infrastructure resources. For example, a discovery engine may reference federated identity information stored in an identity vault and enrich a discovered infrastructure model with the federated identity information. Thus, the model may generally include information describing physical and virtualized resources in the infrastructure, applications and services running in the infrastructure, and information derived from the federated identity information that describes dependencies between the physical resources, the virtualized resources, the applications, and the services.

    摘要翻译: 本文中描述的用于智能工作负载管理系统中的发现丰富的系统和方法可以包括具有用于创建协调线程以管理工作负载的模型驱动的面向服务的架构的计算环境。 特别地,管理线程可以收敛用于管理身份和访问凭证的信息,其可以提供可以丰富物理和虚拟基础设施资源的发现的信息。 例如,发现引擎可以引用存储在身份库中的联合身份信息,并使用联合身份信息来丰富已发现的基础架构模型。 因此,该模型通常可以包括描述在基础设施中运行的基础设施,应用和服务中的物理和虚拟资源的信息,以及从描述物理资源,虚拟化资源,应用和应用之间的依赖关系的联合身份信息导出的信息 服务。

    System and method for discovery enrichment in an intelligent workload management system
    16.
    发明授权
    System and method for discovery enrichment in an intelligent workload management system 失效
    在智能工作负载管理系统中发现丰富的系统和方法

    公开(公告)号:US08695075B2

    公开(公告)日:2014-04-08

    申请号:US12762015

    申请日:2010-04-16

    摘要: The system and method described herein for discovery enrichment in an intelligent workload management system may include a computing environment having a model-driven, service-oriented architecture for creating collaborative threads to manage workloads. In particular, the management threads may converge information for managing identities and access credentials, which may provide information that can enrich discovery of physical and virtual infrastructure resources. For example, a discovery engine may reference federated identity information stored in an identity vault and enrich a discovered infrastructure model with the federated identity information. Thus, the model may generally include information describing physical and virtualized resources in the infrastructure, applications and services running in the infrastructure, and information derived from the federated identity information that describes dependencies between the physical resources, the virtualized resources, the applications, and the services.

    摘要翻译: 本文中描述的用于智能工作负载管理系统中的发现丰富的系统和方法可以包括具有用于创建协调线程以管理工作负载的模型驱动的面向服务的架构的计算环境。 特别地,管理线程可以收敛用于管理身份和访问凭证的信息,其可以提供可以丰富物理和虚拟基础设施资源的发现的信息。 例如,发现引擎可以引用存储在身份库中的联合身份信息,并使用联合身份信息来丰富已发现的基础架构模型。 因此,该模型通常可以包括描述在基础设施中运行的基础设施,应用和服务中的物理和虚拟资源的信息,以及从描述物理资源,虚拟化资源,应用和应用之间的依赖关系的联合身份信息导出的信息 服务。