首页> 外国专利> CONSTRUCTING GRAPH MODELS OF EVENT CORRELATION IN ENTERPRISE SECURITY SYSTEMS

CONSTRUCTING GRAPH MODELS OF EVENT CORRELATION IN ENTERPRISE SECURITY SYSTEMS

机译:企业安全系统中事件关联的图形模型的构建

摘要

Methods and systems for detecting anomalous events include detecting anomalous events (42,43) in monitored system data. An event correlation graph is generated (302) by determining a tendency for a first process to access a system target, include an innate tendency of the first process to access the system target, an influence of previous events from the first process, and an influence of processes other than the first process. Kill chains are generated (310) from the event correlation graph that characterize events in an attack path over time. A security management action is performed (412) based on the kill chains.
机译:用于检测异常事件的方法和系统包括在监视的系统数据中检测异常事件(42,43)。通过确定第一过程访问系统目标的趋势来生成事件相关图(302),该趋势相关图包括第一过程访问系统目标的先天趋势,来自第一过程的先前事件的影响以及影响除第一个流程以外的其他流程。从事件相关图生成(310)杀死链,其表征攻击路径中随着时间的事件。基于查杀链执行安全管理动作(412)。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号