发明名称 Progressive layered forensic correlation of computer network and security events
摘要 Rules are arranged as nodes among layers of a hierarchical decision tree. Nodes of the decision tree can be copied and re-used at other locations on the current tree, or on another tree, in a highly efficient manner. When this occurs, corresponding field values from a parent or ancestor node are automatically updated in the newly introduced node. In addition, when a decision tree is used to operate on an event repository, the results of various rules, defined as a “match” or “no match”, are stored in a common event table that is accessible by nodes at other layers of the decision tree. In addition, actions can be initiated, for example command scripts, at designated nodes of the decision tree, for example upon the occurrence of certain conditions.
申请公布号 US7873717(B1) 申请公布日期 2011.01.18
申请号 US20050145779 申请日期 2005.06.06
申请人 INTERNATIONAL BUSINESS MACHINES CORPORATION 发明人 WOOLWAY ALLAN P.
分类号 G06F15/173;G06F9/44;G06F11/00 主分类号 G06F15/173
代理机构 代理人
主权项
地址