发明名称 TRACKING CHANGING STATE DATA TO ASSIST IN COMPUTER NETWORK SECURITY
摘要 A session table includes one or more records, where each record represents a session. Session record information is stored in various fields, such as key fields, value fields, and timestamp fields. Session information is described as keys and values in order to support query/lookup operations. A session table is associated with a filter, which describes a set of keys that can be used for records in that table. A session table is populated using data contained in security information/events. Rules are created to identify events related to session information, extract the session information, and use the session information to modify a session table. A session table is partitioned so that the number of records in each session table partition is decreased. A session table is processed periodically so that active sessions are moved to the current partition.
申请公布号 EP2076993(A2) 申请公布日期 2009.07.08
申请号 EP20070868579 申请日期 2007.10.25
申请人 ARCSIGHT, INC. 发明人 SINGLA, ANURAG;SAURABH, KUMAR;TIDWELL, KENNY C.
分类号 H04L9/00;G06F17/30;H04L29/06;H04L29/12 主分类号 H04L9/00
代理机构 代理人
主权项
地址