发明名称 SECURITY EVENT MONITORING DEVICE, METHOD, AND PROGRAM
摘要 <P>PROBLEM TO BE SOLVED: To provide a security event monitoring device and the like, even when including an operation impossible to specify an operator, capable of estimating the operator by appropriately detecting a security event. <P>SOLUTION: A security event monitoring device 10 includes: storage means 12 which stores in advance a correlation rule; a log collection unit 101 which receives each log from each monitoring target device; a correlation analysis unit 103 which generates scenario candidates by associating each of the logs; a scenario candidate evaluation unit 104 which calculates an importance degrees of each scenario candidate; and a result display unit 105 which displays/outputs a scenario candidate of a high importance degree. The scenario candidate evaluation unit includes: a user association degree evaluation function 104a which calculates user association degrees; an operation association degree evaluation function 104b which calculates operation association degrees; and a scenario candidate importance reevaluation function 104c which recalculates an importance degree of each of the scenario candidates for every user according to the user association degrees and the operation association degrees. <P>COPYRIGHT: (C)2013,JPO&INPIT
申请公布号 JP2013061794(A) 申请公布日期 2013.04.04
申请号 JP20110199776 申请日期 2011.09.13
申请人 NEC CORP 发明人 MURAMOTO EIJI
分类号 G06F21/31;G06F11/30;G06F11/34;G06Q50/10 主分类号 G06F21/31
代理机构 代理人
主权项
地址