Security system for and method of detecting and responding to cyber attacks on large network systems
    1.
    发明申请
    Security system for and method of detecting and responding to cyber attacks on large network systems 有权
    用于检测和响应大型网络系统的网络攻击的安全系统和方法

    公开(公告)号:US20080010225A1

    公开(公告)日:2008-01-10

    申请号:US11805403

    申请日:2007-05-23

    CPC分类号: G06N7/005

    摘要: An improved security system for and method of detecting and responding to cyber attacks on a network or network element. The system comprises: (a) an intelligent agent-based information retrieval subsystem configured so as to automatically search for and retrieve relevant data from distributed sources; (b) a rule-based inferencing mechanism configured so as to interpret retrieved data within the situational context to support event and alert generation for cyber threat assessment and prediction; and (c) a threat assessment and prediction mechanism configured so as to capture relating to the interrelationship between cyber sensor outputs and cyber attacks.

    摘要翻译: 一种改进的网络或网络元素网络攻击检测和响应方法。 该系统包括:(a)基于智能代理的信息检索子系统,被配置为从分布式源自动搜索和检索相关数据; (b)基于规则的推理机制,被配置为解释情境背景下的检索数据,以支持网络威胁评估和预测的事件和警报生成; 和(c)配置的威胁评估和预测机制,以捕获与网络传感器输出和网络攻击之间的相互关系。