Invention Grant
- Patent Title: Comparing events from multiple network security devices
- Patent Title (中): 比较来自多个网络安全设备的事件
-
Application No.: US10821459Application Date: 2004-04-09
-
Publication No.: US08528077B1Publication Date: 2013-09-03
- Inventor: Kenny Tidwell , Debabrata Dash
- Applicant: Kenny Tidwell , Debabrata Dash
- Applicant Address: US TX Houston
- Assignee: Hewlett-Packard Development Company, L.P.
- Current Assignee: Hewlett-Packard Development Company, L.P.
- Current Assignee Address: US TX Houston
- Main IPC: G06F11/00
- IPC: G06F11/00

Abstract:
Events are received from a plurality of security devices (which may be similar or different devices, e.g., intrusion detection systems configured to monitor network traffic) and divided into a plurality of event flows. Comparing the event flows (e.g., using statistical correlation methods) then generates one or more meta-events. The received events may be divided into different event flows on the basis of the security device which generated the events. The meta-events may be generated by evaluating a perimeter defense device through comparison of the different event flows. In some cases, various ones of the security devices may be inside or outside a perimeter defined by the perimeter defense device.
Information query