System and method of securing web applications across an enterprise
    1.
    发明授权
    System and method of securing web applications across an enterprise 有权
    跨企业保护Web应用程序的系统和方法

    公开(公告)号:US07934253B2

    公开(公告)日:2011-04-26

    申请号:US11532060

    申请日:2006-09-14

    IPC分类号: G06F11/00

    摘要: A system and method for protection of Web based applications are described. The techniques described provide an enterprise wide approach to preventing attacks of Web based applications. Individual computer networks within the enterprise monitor network traffic to identify anomalous traffic. The anomalous traffic can be identified by comparing the traffic to a profile of acceptable user traffic when interacting with the application. The anomalous traffic, or security events, identified at the individual computer networks are communicated to a central security manager. The central security manager correlates the security events at the individual computer networks to determine if there is an enterprise wide security threat. The central security manager can then communicate instructions to the individual computer networks so as to provide an enterprise wide solution to the threat.

    摘要翻译: 描述了一种用于保护基于Web的应用程序的系统和方法。 所描述的技术提供了一种企业级的方法来防止基于Web的应用程序的攻击。 企业内的个人计算机网络监控网络流量,以识别异常流量。 通过在与应用程序交互时将流量与可接受用户流量的配置文件进行比较,可以识别异常流量。 在个别计算机网络上识别的异常流量或安全事件被传送给中央安全管理员。 中央安全经理将各个计算机网络上的安全事件相关联,以确定是否存在企业级的安全威胁。 然后,中央安全经理可以向各个计算机网络传达指令,从而为威胁提供企业级的解决方案。