首页> 外国专利> Detection of security incidents with low confidence security events

Detection of security incidents with low confidence security events

机译:使用低置信度安全事件检测安全事件

摘要

Techniques are disclosed for detecting security incidents based on low confidence security events. A security management server aggregates a collection of security events received from logs from one or more devices. The security management server evaluates the collection of security events based on a confidence score assigned to each distinct type of security event. Each confidence score indicates a likelihood that a security incident has occurred. The security management server determines, based on the confidence scores, at least one threshold for determining when to report an occurrence of a security incident from the collection of security events. Upon determining that at least one security event of the collection has crossed the at least one threshold, the security management server reports the occurrence of the security incident to an analyst.
机译:公开了用于基于低置信度安全事件来检测安全事件的技术。安全管理服务器汇总从一个或多个设备的日志中接收到的安全事件的集合。安全管理服务器基于分配给每种不同类型的安全事件的置信度分数来评估安全事件的集合。每个置信度分数表示发生安全事件的可能性。安全管理服务器基于置信度分数确定至少一个阈值,该阈值用于确定何时从安全事件集合中报告安全事件的发生。在确定集合中的至少一个安全事件已超过至少一个阈值时,安全管理服务器将安全事件的发生报告给分析人员。

著录项

  • 公开/公告号US9888024B2

    专利类型

  • 公开/公告日2018-02-06

    原文格式PDF

  • 申请/专利权人 SYMANTEC CORPORATION;

    申请/专利号US201514871643

  • 发明设计人 KEVIN ROUNDY;MICHAEL SPERTUS;

    申请日2015-09-30

  • 分类号H04L29/06;G06F21/55;H04L12/24;

  • 国家 US

  • 入库时间 2022-08-21 12:54:26

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号