发明名称 |
METHOD AND SYSTEM FOR DISPLAYING NETWORK SECURITY INCIDENTS |
摘要 |
A network security monitor system groups a plurality of security events into network sessions, correlates the network sessions according to a set of predefined network security event correlation rules and generates a security incident for the network sessions that satisfy one of the network security event correlation rules. The system then presents the information of the network sessions and security incidents to a user of the system in an intuitive form. The user is able to not only learn the details of a possible network attack, but also creates new security event correlation rules intuitively, including drop rules for dropping a particular type of events. |
申请公布号 |
EP1665011(A4) |
申请公布日期 |
2014.05.21 |
申请号 |
EP20040788620 |
申请日期 |
2004.09.03 |
申请人 |
PROTEGO NETWORKS, INC. |
发明人 |
BHATTACHARYA, PARTHA;LEE, IMIN, T.;JOSEPH, AJI;STEVENS, ELI;NARAMREDDY, DIWAKAR |
分类号 |
G06F3/00;G06F;H04L9/00;H04L29/06 |
主分类号 |
G06F3/00 |
代理机构 |
|
代理人 |
|
主权项 |
|
地址 |
|