发明名称 |
REAL-TIME IDENTIFICATION OF AN ASSET MODEL AND CATEGORIZATION OF AN ASSET TO ASSIST IN COMPUTER NETWORK SECURITY |
摘要 |
? unique identifier is assigned to a network node and is used to obtain an "asset model" corresponding to the node and to determine whether the node is a member of a particular category. An asset model is a set of information about a node (e.g., the node's role within the enterprise, software installed on the node, and known vulnerabilities/weaknesses of the node). An identifier lookup module determines a node's identifier based on characteristics of the node (such as [P address., host name, network zone, and/or MAC address), which are used as keys into lookup data structures. A category lookup module determines whether a particular node is a member of (i.e., within) a particular category using a transitive closure to model the categories (properties) that can be attached to an asset model. A transitive closure for a particular asset category is stored as a bitmap, similar to bitmap indexing. |
申请公布号 |
WO2008052135(A2) |
申请公布日期 |
2008.05.02 |
申请号 |
WO2007US82562 |
申请日期 |
2007.10.25 |
申请人 |
ARCSIGHT, INC.;LAHOTI, ANKUR;HUANG, HUI;BEEDGEN, CHRISTIAN, F. |
发明人 |
LAHOTI, ANKUR;HUANG, HUI;BEEDGEN, CHRISTIAN, F. |
分类号 |
G06F15/16 |
主分类号 |
G06F15/16 |
代理机构 |
|
代理人 |
|
主权项 |
|
地址 |
|