Invention Grant
US08176527B1 Correlation engine with support for time-based rules 有权
相关引擎,支持基于时间的规则

Correlation engine with support for time-based rules
Abstract:
A rules engine with support for time-based rules is disclosed. A method performed by the rules engine, comprises receiving security events generated by a number of network devices. The security events are aggregated. One or more time-based rules are provided to a RETE engine. The aggregated security events are provided to the RETE engine at specific times associated with the time-based rules. The security events are cross-correlated with the one or more time-based rules; and one or more first stage meta-events are reported.
Information query
Patent Agency Ranking
0/0