-
公开(公告)号:US09866426B2
公开(公告)日:2018-01-09
申请号:US14613159
申请日:2015-02-03
CPC分类号: H04L41/0604 , H04L41/0631 , H04L41/0636 , H04L41/145 , H04L43/026 , H04L63/1408 , H04L63/20 , H04L67/30
摘要: Apparatus and methods facilitate analysis of events associated with network and computer systems. Event data, such as security threats, are comparison matched with event rules of event rule sets associated with each network or computer system to determine whether the items are potentially significant. Additionally, the system-event data may be scored where the score is used for prioritizing system-event data as to their significance. Associated with the comparison matching are various analytics that further analyze event data for measuring and analyzing the system-event data according to various algorithms.
-
公开(公告)号:US20150213358A1
公开(公告)日:2015-07-30
申请号:US14613159
申请日:2015-02-03
CPC分类号: H04L41/0604 , H04L41/0631 , H04L41/0636 , H04L41/145 , H04L43/026 , H04L63/1408 , H04L63/20 , H04L67/30
摘要: Apparatus and methods facilitate analysis of events associated with network and computer systems. Event data, such as security threats, are comparison matched with event rules of event rule sets associated with each network or computer system to determine whether the items are potentially significant. Additionally, the system-event data may be scored where the score is used for prioritizing system-event data as to their significance. Associated with the comparison matching are various analytics that further analyze event data for measuring and analyzing the system-event data according to various algorithms.
摘要翻译: 装置和方法有助于分析与网络和计算机系统有关的事件。 事件数据(例如安全威胁)与与每个网络或计算机系统相关联的事件规则集的事件规则进行比较,以确定项目是否具有潜在的重要性。 此外,系统事件数据可以被评分,其中分数用于对系统事件数据的优先级表示其重要性。 与比较匹配相关的是根据各种算法进一步分析用于测量和分析系统事件数据的事件数据的各种分析。
-