发明名称 Real-Time Identification of an Asset Model and Categorization of an Asset to Assist in Computer Network Security
摘要 A unique identifier is assigned to a network node and is used to obtain an "asset model" corresponding to the node and to determine whether the node is a member of a particular category. An asset model is a set of information about a node (e.g., the node's role within the enterprise, software installed on the node, and known vulnerabilities/weaknesses of the node). An identifier lookup module determines a node's identifier based on characteristics of the node (such as IP address, host name, network zone, and/or MAC address), which are used as keys into lookup data structures. A category lookup module determines whether a particular node is a member of (i.e., within) a particular category using a transitive closure to model the categories (properties) that can be attached to an asset model. A transitive closure for a particular asset category is stored as a bitmap, similar to bitmap indexing.
申请公布号 US2008104276(A1) 申请公布日期 2008.05.01
申请号 US20070923513 申请日期 2007.10.24
申请人 ARCSIGHT, INC. 发明人 LAHOTI ANKUR;HUANG HUI;BEEDGEN CHRISTIAN F.
分类号 G06F15/16 主分类号 G06F15/16
代理机构 代理人
主权项
地址