发明名称 Enterprise security assessment sharing
摘要 An enterprise-wide sharing arrangement uses a semantic abstraction, called a security assessment, to share security-related information between different security products, called endpoints. A security assessment is defined as a tentative assignment by an endpoint of broader contextual meaning to information that is collected about an object of interest. Its tentative nature is reflected in two of its components: a fidelity field used to express the level of confidence in the assessment, and a time-to-live field for an estimated time period for which the assessment is valid. Endpoints may publish security assessments onto a security assessment channel, as well as subscribe to a subset of security assessments published by other endpoints. A specialized endpoint is coupled to the channel that performs as a centralized audit point by subscribing to all security assessments, logging the security assessments, and also logging the local actions taken by endpoints in response to security threats.
申请公布号 US2008229422(A1) 申请公布日期 2008.09.18
申请号 US20070724061 申请日期 2007.03.14
申请人 MICROSOFT CORPORATION 发明人 HUDIS EFIM;HELMAN YAIR;MALKA JOSEPH;BARASH URI
分类号 G06F11/00 主分类号 G06F11/00
代理机构 代理人
主权项
地址