发明名称 Intelligent security engine and intelligent and integrated security system using the same
摘要 A firewall interconnects and controls access between external and internal networks, and a plurality of security agents monitor a data flow and system calls over the internal network. An intelligent security engine (ISE) is for analyzing an alert message, a traffic information and an event information transferred from the plurality of security agents to decide if there is an attack and to generate a signature through a learning process. A security policy manager (SPM) is for managing and applying a security policy to each of the plurality of security agents based on the decision of the ISE. The ISE performs a correlation analysis and a causation analysis on suspicious traffic and events and a detection message transferred from the plurality of security agents. Further, the ISE carries out a pattern analysis and generates a new detection pattern through a self-learning process.
申请公布号 US2004015719(A1) 申请公布日期 2004.01.22
申请号 US20020195326 申请日期 2002.07.16
申请人 LEE DAE-HYUNG;KIM SUNG-CHUL;RYU DU-CHEON 发明人 LEE DAE-HYUNG;KIM SUNG-CHUL;RYU DU-CHEON
分类号 H04L29/06;(IPC1-7):G06F11/30;G06F15/173 主分类号 H04L29/06
代理机构 代理人
主权项
地址