Intrusion detection report correlator and analyzer
    1.
    发明申请
    Intrusion detection report correlator and analyzer 有权
    入侵检测报告相关器和分析仪

    公开(公告)号:US20060070128A1

    公开(公告)日:2006-03-30

    申请号:US11017382

    申请日:2004-12-20

    IPC分类号: G06F12/14

    CPC分类号: H04L63/1416 H04L63/1441

    摘要: A computer/computer network security alert management system aggregates information from multiple intrusion detectors. Utilizing reports from multiple intrusion detectors reduces the high false alarm rate experienced by individual detectors while also improving detection of coordinated attacks involving a series of seemingly harmless operations. An internal representation of a protected enclave is utilized, and intrusion detection system (IDS) information is correlated to accurately prioritize alerts. In one embodiment, the system is capable of utilizing data from most existing IDS products, with flexibility to add further IDS products.

    摘要翻译: 计算机/计算机网络安全警报管理系统聚合来自多个入侵检测器的信息。 利用来自多个入侵检测器的报告可以降低单个检测器所遇到的高错误率,同时还可以改善对涉及一系列看似无害操作的协调攻击的检测。 使用受保护飞地的内部表示,并将入侵检测系统(IDS)信息相关联,以准确地确定警报的优先级。 在一个实施例中,该系统能够利用来自大多数现有IDS产品的数据,并且可以灵活地添加更多的IDS产品。

    Physical security management system
    3.
    发明授权
    Physical security management system 有权
    物理安全管理体系

    公开(公告)号:US08272053B2

    公开(公告)日:2012-09-18

    申请号:US11249622

    申请日:2005-10-13

    IPC分类号: G06F21/00

    摘要: A physical security system having a plurality of sensors and a sensor report aggregator. The sensors may detect a large number of physical activities. The aggregator may cluster a large number of detected reports to a small number of sets of reports. The sets of reports may be reduced to hypotheses. From the hypotheses, the aggregator may develop hypotheses about the physical environment which the sensors are monitoring in view of a security reference model. The security reference model may include, but not be limited to, facility models, physical security models, and/or attack models. The hypotheses may have probabilities assigned to them according to their certitude of likelihood and severity of danger.

    摘要翻译: 具有多个传感器和传感器报告聚合器的物理安全系统。 传感器可以检测大量的身体活动。 聚合器可将大量检测到的报告聚集到少量报告集。 这些报告可能会减少到假设。 根据假设,聚合器可以根据安全参考模型来制定关于传感器正在监控的物理环境的假设。 安全参考模型可以包括但不限于设施模型,物理安全模型和/或攻击模型。 这些假设可能根据他们的可能性和严重程度的危险性分配给他们。

    AUDIO-BASED PRESENTATION SYSTEM
    4.
    发明申请
    AUDIO-BASED PRESENTATION SYSTEM 有权
    基于音频的演示系统

    公开(公告)号:US20080040669A1

    公开(公告)日:2008-02-14

    申请号:US11463292

    申请日:2006-08-08

    摘要: A system for providing audio-based information pertaining to a situation communicated to a first responder en route to the situation. The information may include real-time and current data of the on-going situation (e.g., a building fire). The information may be relayed to the first responder by a dispatch center, or other intermediary, or come directly from monitoring instrumentation at a location of the situation. Also, background and/or preplanned information about the location may be provided to the first responder via a handset or other device. The responder may request certain information via the handset or device in a vehicle en route with voice requests or button activation. Visual displays of information on the instrumentation may be converted to audio- or speech-based displays for the responder.

    摘要翻译: 一种用于提供与在通过该情况的通信给第一响应者的情况有关的音频信息的系统。 该信息可以包括正在进行的情况(例如,建筑物火灾)的实时和当前数据。 该信息可以由调度中心或其他中间人转发到第一响应者,或者直接来自在该情况的位置处的监视仪器。 此外,可以经由手机或其他设备将关于位置的背景和/或预先计划的信息提供给第一响应者。 响应者可以通过具有语音请求或按钮激活的车辆中的手机或设备请求某些信息。 有关仪器信息的视觉显示可以转换为响应者的基于音频或语音的显示。

    System and method for computer service security
    5.
    发明申请
    System and method for computer service security 有权
    计算机服务安全的系统和方法

    公开(公告)号:US20070220135A1

    公开(公告)日:2007-09-20

    申请号:US11377740

    申请日:2006-03-16

    IPC分类号: G06F15/173

    摘要: In an embodiment, a computer-based service security system receives a communication such as a query. The system processes that query in a server, which may be referred to as a lead server, and creates a plurality of copies of that lead server. The query is transferred to the plurality of copies of the lead server when the query did not cause a problem in the lead server. The query is transferred to a learning server when the query caused a problem in the lead server. The lead server is replaced by one of the copies of the lead server when the query caused a problem on the lead server.

    摘要翻译: 在一个实施例中,基于计算机的服务安全系统接收诸如查询的通信。 系统处理在服务器中的查询,该服务器可以被称为主导服务器,并且创建该引导服务器的多个副本。 当查询在引导服务器中没有引起问题时,将查询转移到主导服务器的多个副本。 当查询导致首席服务器出现问题时,该查询将传输到学习服务器。 当主导服务器发生问题时,主导服务器被主导服务器的一个副本替换。

    Physical security management system
    7.
    发明申请
    Physical security management system 有权
    物理安全管理体系

    公开(公告)号:US20060059557A1

    公开(公告)日:2006-03-16

    申请号:US11249622

    申请日:2005-10-13

    IPC分类号: G06F12/14

    摘要: A physical security system having a plurality of sensors and a sensor report aggregator. The sensors may detect a large number of physical activities. The aggregator may cluster a large number of detected reports to a small number of sets of reports. The sets of reports may be reduced to hypotheses. From the hypotheses, the aggregator may develop hypotheses about the physical environment which the sensors are monitoring in view of a security reference model. The security reference model may include, but not be limited to, facility models, physical security models, and/or attack models. The hypotheses may have probabilities assigned to them according to their certitude of likelihood and severity of danger.

    摘要翻译: 具有多个传感器和传感器报告聚合器的物理安全系统。 传感器可以检测大量的身体活动。 聚合器可将大量检测到的报告聚集到少量报告集。 这些报告可能会减少到假设。 根据假设,聚合器可以根据安全参考模型来制定关于传感器正在监控的物理环境的假设。 安全参考模型可以包括但不限于设施模型,物理安全模型和/或攻击模型。 这些假设可能根据他们的可能性和严重程度的危险性分配给他们。