发明名称 Real time monitoring and analysis of events from multiple network security devices
摘要 Security events generated by a number of network devices are gathered and normalized to produce normalized security events in a common schema. The normalized security events are cross-correlated according to rules to generate meta-events. The security events may be gathered remotely from a system at which the cross-correlating is performed. Any meta-events that are generated may be reported by generating alerts for display at one or more computer consoles, or by sending an e-mail message, a pager message, a telephone message, and/or a facsimile message to an operator or other individual. In addition to reporting the meta-events, the present system allows for taking other actions specified by the rules, for example executing scripts or other programs to reconfigure one or more of the network devices, and or to modify or update access lists, etc.
申请公布号 US8056130(B1) 申请公布日期 2011.11.08
申请号 US20080098322 申请日期 2008.04.04
申请人 HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P. 发明人 NJEMANZE HUGH S.;KOTHARI PRAVIN S.
分类号 G06F21/00;G06F15/16 主分类号 G06F21/00
代理机构 代理人
主权项
地址