发明名称 MAPPING BETWEEN USERS AND MACHINES IN AN ENTERPRISE SECURITY ASSESSMENT SHARING SYSTEM
摘要 Mapping between object types in an enterprise security assessment sharing ("ESAS") system enables attacks on an enterprise network and security incidents to be better detected and capabilities to respond to be improved. The ESAS system is distributed among endpoints incorporating different security products in the enterprise network that share a commonly-utilized communications channel. An endpoint will generate a tentative assignment of contextual meaning called a security assessment that is published when a potential security incident is detected. The security assessment identifies the object of interest, the type of security incident and its severity. A level of confidence in the detection is also provided which is expressed by an attribute called the "fidelity". ESAS is configured with the capabilities to map between objects, including users and machines in the enterprise network, so that security assessments applicable to one object domain can be used to generate security assessments in another object domain.
申请公布号 US2009328222(A1) 申请公布日期 2009.12.31
申请号 US20080146440 申请日期 2008.06.25
申请人 MICROSOFT CORPORATION 发明人 HELMAN YAIR;HUDIS EFIM;ARZI LIOR
分类号 G06F21/00 主分类号 G06F21/00
代理机构 代理人
主权项
地址