发明名称 Method and apparatus for exercising and debugging correlations for network security system
摘要 A selected time interval of previously stored security events generated by a number of computer network devices are replayed and cross-correlated according to rules defining security incidents. Meta-events are generated when the security events satisfy conditions associated with one or more of the rules. The rules used during replay may differ from prior rules used at a time when the security events occurred within a computer network that included the computer network devices. In this way, new rules can be tested against true security event data streams to determine whether or not the rules should be used in a live environment (i.e., the efficacy of the rules can be tested and/or debugged against actual security event data).
申请公布号 US7899901(B1) 申请公布日期 2011.03.01
申请号 US20020308416 申请日期 2002.12.02
申请人 ARCSIGHT, INC. 发明人 NJEMANZE HUGH S.;DASH DEBABRATA;WANG SHIJIE
分类号 G06F15/173;G06F9/00;G06F11/00 主分类号 G06F15/173
代理机构 代理人
主权项
地址