首页> 外国专利> METHOD FOR RISK MANAGEMENT ANALYSIS BASED ON VULNERABILITY ASSESSMENT AND APPARATUS THEREOF

METHOD FOR RISK MANAGEMENT ANALYSIS BASED ON VULNERABILITY ASSESSMENT AND APPARATUS THEREOF

机译:基于脆弱性评估的风险管理分析方法及其装置

摘要

A device and a method for analyzing risk management based on network vulnerability evaluation are provided to increase analysis performance by considering relation between alarm data and vulnerability information, analyze correlation with a current countermeasure policy in addition, and use only the actually needed alarm data. A preprocessor(300) discriminates an attack type of the alarm data generated in the network according to a source/destination IP(Internet Protocol), an attack name, and presence of a port number according to a service sort. A database processor(350) collects and stores the vulnerability information for network assets by using a vulnerability analyzer. A correlation analyzer(310) associates the alarm data according to the presence of the destination IP, the attack name, and the port number, and opening of the port with the presence of the stored vulnerability information for the asset. A countermeasure processor(330) generates or revokes an alarm depending on an association result, and generates the countermeasure policy corresponding to the alarm.
机译:提供了一种基于网络漏洞评估的风险管理分析装置和方法,以通过考虑警报数据和漏洞信息之间的关系来提高分析性能,另外还与当前的对策策略进行关联分析,并且仅使用实际需要的警报数据。预处理器(300)根据源/目的地IP(互联网协议),在网络中根据服务种类来区分在网络中生成的警报数据的攻击类型,攻击名称和端口号的存在。数据库处理器(350)通过使用漏洞分析器来收集和存储网络资产的漏洞信息。相关分析器(310)根据目的地IP的存在,攻击名称和端口号,以及端口的开放与所存储的资产的漏洞信息的存在来将警报数据相关联。对策处理器(330)根据关联结果生成或撤销警报,并生成与警报相对应的对策策略。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号