首页> 外国专利> System and method for intrusion decision-making in autonomic computing environments

System and method for intrusion decision-making in autonomic computing environments

机译:自主计算环境中入侵决策的系统和方法

摘要

A mechanism is provided for performing intrusion decision-making using a plurality of approaches. Detection approaches may include, for example, signature-based, anomaly-based, scan-based, and danger theory approaches. When event information is received, each approach produces a result. A consensus of each result is then reached by using, for example, Bayesian Filtering. A corpus is kept for each approach. An intrusion corpus keeps combinations of the corpora for all of the approaches that constitute intrusions. A safe corpus keeps combinations of the corpora for all of the approaches that do not constitute an intrusion. The corpora for the approaches may be pre-defined according to security policies and the like. The intrusion corpus and the safe corpus may be trained using scores that are determined using the detection approaches.
机译:提供了一种用于使用多种方法来执行入侵决策的机制。检测方法可以包括例如基于签名,基于异常,基于扫描和危险理论的方法。收到事件信息后,每种方法都会产生结果。然后通过使用例如贝叶斯过滤来达到每个结果的共识。每种方法都会保留一个语料库。入侵语料库为构成入侵的所有方法保留语料库的组合。一个安全的语料库会为所有不构成入侵的方法保留语料库的组合。可以根据安全策略等预先定义用于这些方法的语料库。可以使用使用检测方法确定的分数来训练入侵语料库和安全语料库。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号