Computer-implemented method and system for security event correlation
    4.
    发明授权
    Computer-implemented method and system for security event correlation 有权
    计算机实现的安全事件相关方法和系统

    公开(公告)号:US07673335B1

    公开(公告)日:2010-03-02

    申请号:US10975374

    申请日:2004-10-29

    IPC分类号: G06F12/14

    CPC分类号: G06F21/554 G06F21/552

    摘要: A system and method for analyzing events from devices relating to network security, includes a device interface(s), for receiving events from devices. One or more processors, responsive to the event received pursuant to the device interfaces, evaluate the event in accordance with rules, wherein the rules define, inter alia, an operation the system is to take to evaluate the event and an action to be taken under specified conditions. Also, the processor can determine, responsive to the received event, whether the event is of interest, and if not, discarding the event. The processor can provide a correlation corresponding to the at least one event, for the rules.

    摘要翻译: 用于分析与网络安全有关的设备的事件的系统和方法包括用于从设备接收事件的设备接口。 响应于根据设备接口接收到的事件的一个或多个处理器根据规则来评估事件,其中规则除其他外定义系统要采取的操作以评估事件和要采取的行动 指定条件。 此外,处理器可以响应于所接收的事件来确定事件是否是感兴趣的,如果不是,则丢弃该事件。 对于规则,处理器可以提供对应于至少一个事件的相关性。

    TECHNIQUES FOR PRIVILEGED NETWORK ROUTING
    5.
    发明申请
    TECHNIQUES FOR PRIVILEGED NETWORK ROUTING 有权
    特殊网络路由技术

    公开(公告)号:US20120281557A1

    公开(公告)日:2012-11-08

    申请号:US13100082

    申请日:2011-05-03

    IPC分类号: H04L12/56 H04L12/26

    CPC分类号: H04L45/308 H04L45/04

    摘要: Techniques for privileged network routing are provided. As traffic is received at a gateway of a network backbone provider environment it is interrogated for predefined criteria. If the traffic satisfies the predefined criteria, then the information is routed within the network backbone provider environment to use a set of reserved and restricted resources to provide premium service for the traffic being routed through the network backbone provider environment.

    摘要翻译: 提供特权网路路由技术。 由于在网络骨干供应商环境的网关处接收到流量,所以要询问预定义的标准。 如果流量满足预定义的标准,则信息在网络骨干提供者环境内路由以使用一组预留和受限的资源来为通过网络骨干提供者环境路由的流量提供优质服务。

    Techniques for privileged network routing
    7.
    发明授权
    Techniques for privileged network routing 有权
    特权网路路由技术

    公开(公告)号:US08693327B2

    公开(公告)日:2014-04-08

    申请号:US13100082

    申请日:2011-05-03

    IPC分类号: H04L1/00

    CPC分类号: H04L45/308 H04L45/04

    摘要: Techniques for privileged network routing are provided. As traffic is received at a gateway of a network backbone provider environment it is interrogated for predefined criteria. If the traffic satisfies the predefined criteria, then the information is routed within the network backbone provider environment to use a set of reserved and restricted resources to provide premium service for the traffic being routed through the network backbone provider environment.

    摘要翻译: 提供特权网路路由技术。 由于在网络骨干供应商环境的网关处接收到流量,所以要询问预定义的标准。 如果流量满足预定义的标准,则信息在网络骨干提供者环境内路由以使用一组预留和受限的资源来为通过网络骨干提供者环境路由的流量提供优质服务。

    System and method for correlating events in a pluggable correlation architecture
    10.
    发明授权
    System and method for correlating events in a pluggable correlation architecture 有权
    在可插拔相关架构中关联事件的系统和方法

    公开(公告)号:US08185488B2

    公开(公告)日:2012-05-22

    申请号:US12081540

    申请日:2008-04-17

    IPC分类号: G06F17/00 G06N5/02

    CPC分类号: G06N5/022

    摘要: A system for pluggable event correlation may include an input manager that receives a plurality of events and converts the events into a format compatible with one or more of a plurality of correlation engines. The correlation engines may then evaluate the converted events using various rules and generate correlated events when the evaluated events trigger at least one of the rules. An action manager may execute remedial actions when the correlation engines generate the correlated events. Moreover, extensibility may be provided by enabling a user to define rules to be triggered when events occur in a predetermined pattern, and actions to be executed when a predetermined rule triggers a correlated event. Further, to plug a new correlation engine into the system, adapters may be deployed to handle input and output, while the user-defined rules may be validating according to semantic requirements of the new correlation engine.

    摘要翻译: 用于可插拔事件相关的系统可以包括输入管理器,其接收多个事件并将事件转换成与多个相关引擎中的一个或多个相兼容的格式。 然后,相关引擎可以使用各种规则评估转换的事件,并且当评估的事件触发至少一个规则时产生相关事件。 当相关引擎产生相关事件时,动作管理器可以执行补救动作。 此外,可以通过使用户能够定义当事件以预定模式发生时要触发的规则以及当预定规则触发相关事件时要执行的动作来提供可扩展性。 此外,为了将新的相关引擎插入到系统中,可以部署适配器来处理输入和输出,而用户定义的规则可以根据新的相关引擎的语义要求进行验证。