首页> 外国专利> PROFILING CYBER THREATS DETECTED IN A TARGET ENVIRONMENT AND AUTOMATICALLY GENERATING ONE OR MORE RULE BASES FOR AN EXPERT SYSTEM USABLE TO PROFILE CYBER THREATS DETECTED IN A TARGET ENVIRONMENT

PROFILING CYBER THREATS DETECTED IN A TARGET ENVIRONMENT AND AUTOMATICALLY GENERATING ONE OR MORE RULE BASES FOR AN EXPERT SYSTEM USABLE TO PROFILE CYBER THREATS DETECTED IN A TARGET ENVIRONMENT

机译:对目标环境中检测到的网络威胁进行配置分析,并自动生成一个或多个规则库,用于可用于配置目标环境中检测到的网络威胁的专家系统

摘要

A computer implemented method of profiling cyber threats detected in a target environment, comprising: receiving, from a Security Information and Event Manager (SIEM) monitoring the target environment, alerts triggered by a detected potential cyber threat, and, for each alert: retrieving captured packet data related to the alert; extracting data pertaining to a set of attributes from captured packet data triggering the alert; applying fuzzy logic to data pertaining to one or more of the attributes to determine values for one or more output variables indicative of a level of an aspect of risk attributable to the cyber threat.
机译:一种计算机实现的对目标环境中检测到的网络威胁进行概要分析的方法,包括:从监视目标环境的安全信息和事件管理器(SIEM)接收由检测到的潜在网络威胁触发的警报,并且对于每个警报:检索捕获的与警报有关的分组数据;从捕获的触发警报的分组数据中提取与一组属性有关的数据;将模糊逻辑应用于与一个或多个属性有关的数据,以确定一个或多个输出变量的值,这些值指示可归因于网络威胁的风险方面的水平。

著录项

  • 公开/公告号US2017085588A1

    专利类型

  • 公开/公告日2017-03-23

    原文格式PDF

  • 申请/专利权人 CYBERLYTIC LIMITED;

    申请/专利号US201615337120

  • 申请日2016-10-28

  • 分类号H04L29/06;G06N7/02;

  • 国家 US

  • 入库时间 2022-08-21 13:48:21

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号