会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 10. 发明授权
    • Prioritizing Bayes network alerts
    • 优先考虑贝叶斯网络警报
    • US07379993B2
    • 2008-05-27
    • US09952080
    • 2001-09-13
    • Alfonso De Jesus ValdesMartin Wayne FongPhillip Andrew Porras
    • Alfonso De Jesus ValdesMartin Wayne FongPhillip Andrew Porras
    • G06F15/16
    • H04L41/16H04L41/142H04L63/1416H04L63/20
    • This invention uses Bayesian techniques to prioritize alerts or alert groups generated by intrusion detection systems and other information security devices, such as network analyzers, network monitors, firewalls, antivirus software, authentication services, host and application security services, etc. In a preferred embodiment, alerts are examined for the presence of one or more relevant features, such as the type of an attack, the target of an attack, the outcome of an attack, etc. At least a subset of the features is then provided to a real-time Bayes network, which assigns relevance scores to the received alerts or alert groups. In another embodiment, a network manager (a person) can disagree with the relevance score assigned by the Bayes network, and give an alert or alert group a different relevance score. The Bayes network is then modified so that similar future alerts or alert groups will be assigned a relevance score that more closely matches the score given by the network manager.
    • 本发明使用贝叶斯技术对由入侵检测系统和其他信息安全设备(诸如网络分析器,网络监视器,防火墙,防病毒软件,认证服务,主机和应用安全服务等)生成的警报或警报组进行优先级排序。在优选实施例中 检查警报是否存在一个或多个相关特征,例如攻击的类型,攻击的目标,攻击的结果等。然后,将至少一个特征的子集提供给实时的, 时间贝叶斯网络,其将相关性分数分配给接收到的警报或警报组。 在另一个实施例中,网络管理员(个人)可以不同意由贝叶斯网络分配的相关性得分,并给予警报或警报组不同的相关性得分。 然后修改贝叶斯网络,以便将类似的未来警报或警报组分配给与网络管理员给出的得分更接近的相关性分数。