发明名称 Message parsing in a network security system
摘要 Device discovery can be made efficient using certain embodiments of the present invention. In one embodiment, the present invention includes accessing a message in a message log, wherein the message log associates a host identifier with the message, the host identifier being an identifier of a host that sent the message to the message log. Then a list of parsers associated with the host identifier associated with the message can be accessed and parsing the message using parsers from the list of parsers associated with the host identifier can be attempted. If the parsing is unsuccessful, a device type of an originator of the message can be discovered, and a parser associated with the discovered device type can be added to the list of parsers associated with the host identifier.
申请公布号 US7844999(B1) 申请公布日期 2010.11.30
申请号 US20050070024 申请日期 2005.03.01
申请人 ARCSIGHT, INC. 发明人 AGUILAR-MACIAS HECTOR;SUBRAHMANYAM RAJIV
分类号 G06F7/04;G06F3/00;G06F9/00;G06F15/173;H04L29/06 主分类号 G06F7/04
代理机构 代理人
主权项
地址