会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 50. 发明授权
    • 보안 시스템의 로그 분석 시스템 및 방법
    • 安全系统的日志分析系统及其方法
    • KR101239401B1
    • 2013-03-06
    • KR1020120110947
    • 2012-10-05
    • 강명훈
    • 강명훈
    • G06F21/00G06F17/00
    • H04L63/1416H04L63/1408H04L63/168H04L67/02H04L67/10
    • PURPOSE: A log analysis system of a security system and a method thereof are provided to prepare a quantitative basis which improves rule correctness by improving analysis correctness and increasing analysis quantity. CONSTITUTION: A security system(3) stores a log DB(DataBase)(4) by generating log information according to a security rule by monitoring communication content between normal systems. A log analysis unit(6) collects log information including attack content from the log information. If attack content data is based on a web request, the log analysis unit normalizes text based on a rule pattern and an HTTP(Hypertext Transfer Protocol) indicator. A log screen unit(5) displays the normalized log information according to an operator request. [Reference numerals] (1) General system; (2) Computer network; (3) Security system; (31) Log integrated security system; (4) Log DataBase; (5) Log screen unit; (61) Log collecting unit; (62) HTTP indicator-based text normalization processing unit; (63) Rule pattern-based text normalization processing unit; (AA) Rule generating unit; (BB) Traffic collecting unit; (CC) Traffic VS rule comparing unit; (DD) Log generating unit
    • 目的:提供安全系统的日志分析系统及其方法,准备一个定量的基础,通过提高分析正确性和增加分析量,提高规则的正确性。 规定:安全系统(3)通过监视普通系统之间的通信内容,通过根据安全规则生成日志信息来存储日志DB(DataBase)(4)。 日志分析单元(6)从日志信息中收集包含攻击内容的日志信息。 如果攻击内容数据基于Web请求,则日志分析单元基于规则模式和HTTP(超文本传输​​协议)指示符对文本进行规范化。 日志屏幕单元(5)根据操作者请求显示归一化的日志信息。 (附图标记)(1)一般系统; (2)计算机网络; (3)安全系统; (31)日志综合安全系统; (4)Log DataBase; (5)日志屏幕单元; (61)日志收集单元; (62)基于HTTP指标的文本归一化处理单元; (63)基于规则模式的文本归一化处理单元; (AA)规则生成单元; (BB)交通采集单位; (CC)交通VS规则比较单位; (DD)日志生成单元