发明名称 DETECTING NETWORK INTRUSION AND ANOMALY INCIDENTS
摘要 In an embodiment, a method comprises: using computing apparatus, receiving one or more data streams, determining one or more characteristics of the one or more data streams, and based on the one or more characteristics of the one or more data streams, determining one or more tags for the one or more data streams; determining whether the one or more tags indicate one or more malicious patterns representative of network intrusions; in response to determining that the one or more tags indicate one or more malicious patterns representative of network intrusions: generating, based on the one or more tags, one or more aggregated alert streams; applying one or more rules to the one or more aggregated alert streams and receiving a result indicating whether a network intrusion is in progress; in response thereto, determining and executing one or more remedial actions.
申请公布号 US2014230062(A1) 申请公布日期 2014.08.14
申请号 US201313962863 申请日期 2013.08.08
申请人 Cisco Technology, Inc. 发明人 Kumaran Vikram
分类号 G06F21/56 主分类号 G06F21/56
代理机构 代理人
主权项 1. A computer-implemented data processing method comprising: using computing apparatus, receiving one or more data streams, determining one or more characteristics of the one or more data streams, and based on the one or more characteristics of the one or more data streams, determining one or more tags for the one or more data streams; using computing apparatus, determining whether the one or more tags indicate one or more malicious patterns representative of network intrusions; using computing apparatus, in response to determining that the one or more tags indicate one or more malicious patterns representative of network intrusions: generating, based on the one or more tags, one or more aggregated alert streams;applying one or more rules to the one or more aggregated alert streams and receiving a result indicating whether a network intrusion is in progress;in response to receiving the result indicating that the network intrusion is in progress, determining and executing one or more remedial actions.
地址 San Jose CA US