发明名称 Threat detection in a network security system
摘要 A network security system is provided that receives information from various sensors and can analyze the received information. In one embodiment of the present invention, such a system receives a security event from a software agent. The received security event includes a target address and an event signature, as generated by the software agent. The event signature can be used to determine a set of vulnerabilities exploited by the received security event, and the target address can be used to identify a target asset within the network. By accessing a model of the target asset, a set of vulnerabilities exposed by the target asset can be retrieved. Then, a threat can be detected by comparing the set of vulnerabilities exploited by the security event to the set of vulnerabilities exposed by the target asset.
申请公布号 US7861299(B1) 申请公布日期 2010.12.28
申请号 US20070836251 申请日期 2007.08.09
申请人 ARCSIGHT, INC. 发明人 TIDWELL KENNY C.;SAURABH KUMAR;DASH DEBABRATA;NJEMANZE HUGH S.;KOTHARI PRAVIN S.
分类号 G06F11/00 主分类号 G06F11/00
代理机构 代理人
主权项
地址