发明名称 Computer-implemented method and system for security event correlation
摘要 A system and method for analyzing events from devices relating to network security, includes a device interface(s), for receiving events from devices. One or more processors, responsive to the event received pursuant to the device interfaces, evaluate the event in accordance with rules, wherein the rules define, inter alia, an operation the system is to take to evaluate the event and an action to be taken under specified conditions. Also, the processor can determine, responsive to the received event, whether the event is of interest, and if not, discarding the event. The processor can provide a correlation corresponding to the at least one event, for the rules.
申请公布号 US7673335(B1) 申请公布日期 2010.03.02
申请号 US20040975374 申请日期 2004.10.29
申请人 NOVELL, INC. 发明人 CHAKRAVARTY DIPTO;ZAJICEK OFER;PELLEGRINO FRANK;CHOUDHARY USMAN;GASSNER JOHN;ANTONY MELVIN
分类号 G06F12/14 主分类号 G06F12/14
代理机构 代理人
主权项
地址