会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 10. 发明申请
    • Threat scoring system and method for intrusion detection security networks
    • 入侵检测安全网络的威胁评分系统和方法
    • US20070169194A1
    • 2007-07-19
    • US11321620
    • 2005-12-29
    • Christopher ChurchMikhail GovshteynChristopher BakerChristopher Holm
    • Christopher ChurchMikhail GovshteynChristopher BakerChristopher Holm
    • G06F12/14
    • H04L63/1416G06F21/552G06F21/554
    • Embodiments of the invention provide a security expert system (SES) that automates intrusion detection analysis and threat discovery that can use fuzzy logic and forward-chaining inference engines to approximate human reasoning process. Embodiments of the SES can analyze incoming security events and generate a threat rating that indicates the likelihood of an event or a series of events being a threat. In one embodiment, the threat rating is determined based on an attacker rating, a target rating, a valid rating, and, optionally, a negative rating. In one embodiment, the threat rating may be affected by a validation flag. The SES can analyze the criticality of assets and calibrate/recalibrate the severity of an attack accordingly to allow for triage. The asset criticality can have a user-defined value. This ability allows the SES to protect and defend critical network resources in a discriminating and selective manner if necessary (e.g., many attacks).
    • 本发明的实施例提供一种安全专家系统(SES),其自动化可以使用模糊逻辑和前向链接推理机来近似人类推理过程的入侵检测分析和威胁发现。 SES的实施例可以分析传入的安全事件并产生威胁等级,其指示事件或一系列事件成为威胁的可能性。 在一个实施例中,威胁等级是基于攻击者等级,目标等级,有效等级以及可选地为负的等级来确定的。 在一个实施例中,威胁等级可能受到验证标志的影响。 SES可以分析资产的关键性,并相应地校准/重新校准攻击的严重性,以便进行分诊。 资产重要性可以具有用户定义的值。 这种能力允许SES以必要的方式(例如,许多攻击)以辨别和选择的方式来保护和保护关键网络资源。