发明名称 Automatic analysis of security related incidents in computer networks
摘要 <p>Solutions for responding to security-related incidents in a computer network, including a security server, and a client-side arrangement. The security server includes an event collection module communicatively coupled to the computer network, an event analysis module operatively coupled to the event collection module, and a solution module operatively coupled to the event analysis module. The event collection module is configured to obtain incident-related information that includes event-level information from at least one client computer of the plurality of client computers, the incident-related information being associated with at least a first incident which was detected by that at least one client computer and provided to the event collection module in response to that detection. The event analysis module is configured to reconstruct at least one chain of events causally related to the first incident and indicative of a root cause of the first incident based on the incident-related information. The solution module is configured to formulate at least one recommendation for use by the at least one client computer, the at least one recommendation being based on the at least one chain of events, and including corrective/preventive action particularized for responding to the first incident.</p>
申请公布号 EP2566130(A1) 申请公布日期 2013.03.06
申请号 EP20120158171 申请日期 2012.03.06
申请人 KASPERSKY LAB, ZAO 发明人 ZAITSEV, OLEG V.
分类号 H04L29/06 主分类号 H04L29/06
代理机构 代理人
主权项
地址