发明名称 CONTEXT-AWARE NETWORK FORENSICS
摘要 Systems and methods for management of security events and their related forensic context are disclosed. Network forensics involves monitoring and analyzing data flows in a network to assist security analysts to review, analyze and remove a security threat. Security threats in a network environment are generally detected by one or more devices on the network. If a security threat is determined to be severe or significant enough, a security event corresponding to the security threat is often created and stored in the system. To assist in future review and analysis of security threats, timely and relevant context information about network security events may be obtained and stored along with each security event. The forensic context may be accessible to security administrators viewing the security events to provide detailed information about the circumstances surrounding a security event.
申请公布号 WO2015069243(A1) 申请公布日期 2015.05.14
申请号 WO2013US68779 申请日期 2013.11.06
申请人 MCAFEE, INC. 发明人 GUPTA, BIKRAM, KUMAR;SHANKAR, ARUN
分类号 G06F21/50;G06F11/30;G06F15/16 主分类号 G06F21/50
代理机构 代理人
主权项
地址