发明名称 SUPPRESSION OF FALSE ALARMS IN ALARMS ARISING FROM INTRUSION DETECTION PROBES IN A MONITORED INFORMATION SYSTEM
摘要 <p>The invention relates to a system and method for the suppression of false alarms in alarms arising from intrusion detection probes (13a, 13b, 13c) in a monitored information system (1) comprising entities (9, 11a, 11b) producing attacks associated with said alarms and a system for the management of alarms (15), comprising the following steps: -definition, by means of a false alarm suppression module (23), of qualitative relations between the entities (9, 11a, 11b) and a set of profiles; definition, by means of the false alarm suppression module (23), of nominative relations between the set of profiles and a set of names of attacks that the set of profiles is reputed to produce; qualification, by means of the false alarm suppression module (23),of an alarm given by a false alarm if the entity (9, 11a, 11b) involved in the given alarm has a profile which is reputed to produce the attack associated with said given alert.</p>
申请公布号 WO2005122522(A1) 申请公布日期 2005.12.22
申请号 WO2005FR01142 申请日期 2005.05.09
申请人 FRANCE TELECOM;MORIN, BENJAMIN;DEBAR, HERVE 发明人 MORIN, BENJAMIN;DEBAR, HERVE
分类号 G06F21/55;H04L29/06;H04L29/08;(IPC1-7):H04L29/06;G06F1/00 主分类号 G06F21/55
代理机构 代理人
主权项
地址