发明名称 DETECTION OF ADVANCED PERSISTENT THREAT ATTACK ON A PRIVATE COMPUTER NETWORK
摘要 A system for detecting an advanced persistent threat (APT) attack on a private computer network includes hosts computers that receive network traffic and process the network traffic to identify an access event that indicates access to a critical asset of an organization that owns or maintains the private computer network. The critical asset may be a computer that stores confidential data of the organization. Access events may be stored in an event log as event data. Access events indicated in the event log may be correlated using a set of alert rules to identify an APT attack.
申请公布号 US2017099306(A1) 申请公布日期 2017.04.06
申请号 US201514873627 申请日期 2015.10.02
申请人 Trend Micro Incorporated 发明人 CHIU Li-Hsiang;CHANG Wei-Ching;WENG Shih-Hao
分类号 H04L29/06 主分类号 H04L29/06
代理机构 代理人
主权项 1. A system for detecting an advanced persistent threat (APT) attack on a private computer network of an organization, the system comprising: a plurality of hosts computers, the plurality of hosts computers receives network traffic over the private computer network, parses the network traffic to generate event data that indicate access to particular computers on the private computer network that store confidential data of the organization, and transmits the event data over the private computer network; and an APT detection server comprising one or more computers that receive the event data from the plurality of hosts computers, store the event data in an event log, and correlate data in the event log using a set of alert rules to detect an APT attack by identifying an anomalous access to one or more of the particular computers.
地址 Tokyo JP