发明名称 IDS Sensor Placement Using Attack Graphs
摘要 Embodiments of the present invention identify locations to deploy IDS sensor(s) within a network infrastructure and prioritize IDS alerts using attack graph analysis. An attack graph that describes exploitable vulnerability(ies) within a network infrastructure is aggregated into protection domains. Edge(s) that have exploit(s) between two protection domains are identified. Sets that contain edge(s) serviced by a common network traffic device are defined. Set(s) that collectively contain all of the edge(s) are selected. The common network traffic device(s) that service the selected sets are identified as the location(s) to deploy IDS sensor(s) within the network infrastructure.
申请公布号 US2010058456(A1) 申请公布日期 2010.03.04
申请号 US20090548115 申请日期 2009.08.26
申请人 JAJODIA SUSHIL;NOEL STEVEN E 发明人 JAJODIA SUSHIL;NOEL STEVEN E.
分类号 G06F15/16 主分类号 G06F15/16
代理机构 代理人
主权项
地址