发明名称 Hierarchical architecture in a network security system
摘要 A network security system having a hierarchical configuration is provided. In one embodiment the present invention includes a plurality of subsystems, where each subsystem includes a plurality of distributed software agents configured to collect base security events from monitor devices, and a local manager module coupled to the plurality of distributed software agents to generate correlated events by correlating the base security events. Each subsystem can also include a filter coupled to the manager module to select which base security events are to be processed further. The selected base security events are passed to a global manager module coupled to the plurality of subsystems that generates global correlated events by correlating the base security events selected for further processing by each filter of each subsystem.
申请公布号 US9027120(B1) 申请公布日期 2015.05.05
申请号 US200310683191 申请日期 2003.10.10
申请人 Hewlett-Packard Development Company, L.P. 发明人 Tidwell Kenny;Beedgen Christian;Njemanze Hugh S.;Kothari Pravin S.
分类号 G06F12/14;G06F21/60 主分类号 G06F12/14
代理机构 代理人
主权项 1. A network security system comprising: a plurality of subsystems, each subsystem comprising: a plurality of distributed software agents, each agent configured: to collect a base security event from a monitor device; andto transmit the base security event;a local manager module coupled to the plurality of distributed software agents, configured: to receive, from each agent, the base security event;to generate one or more local correlated events by correlating the received base security events, wherein a local correlated event comprises a conclusion drawn from the received base security events according to a rule based on at least a vulnerability of a target network node, the rule grouping security incidents associated with the base security events into a plurality of threat levels, and wherein the conclusion indicates that a plurality of the received base security events is associated with a same security incident; andto transmit the one or more local correlated events; anda filter coupled to the local manager module, configured: to receive the one or more local correlated events;to select local correlated events; andto transmit the selected local correlated events; and a global manager module coupled to the plurality of subsystems, comprising a processor configured: to receive, from each subsystem, the selected local correlated events; andto generate one or more global correlated events by correlating the received selected local correlated events, wherein a global correlated event comprises a second conclusion drawn from the received selected local correlated events according to a second rule, and wherein the second conclusion indicates that a plurality of the received selected local correlated events is associated with a second same security incident.
地址 Houston TX US