发明名称 Method and architecture for online classification-based intrusion alert correlation
摘要 A method and architecture for on-line classification-based intrusion alert correlation are provided. This method applies layered architecture to split and correlate alerts. An alert-splitting technique is used to separate mostly general alerts from more valuable or complicated alerts. Only more important alerts are selected to correlate with known attack scenarios to discover important attack information. Therefore, the disadvantages in the prior art where correlation is shielded and over-consumption of computation resource are solved.
申请公布号 US2007008098(A1) 申请公布日期 2007.01.11
申请号 US20050177803 申请日期 2005.07.08
申请人 WONG HSING-KUO 发明人 WONG HSING-KUO
分类号 G08B29/00 主分类号 G08B29/00
代理机构 代理人
主权项
地址