Invention Grant
US08528077B1 Comparing events from multiple network security devices 有权
比较来自多个网络安全设备的事件

Comparing events from multiple network security devices
Abstract:
Events are received from a plurality of security devices (which may be similar or different devices, e.g., intrusion detection systems configured to monitor network traffic) and divided into a plurality of event flows. Comparing the event flows (e.g., using statistical correlation methods) then generates one or more meta-events. The received events may be divided into different event flows on the basis of the security device which generated the events. The meta-events may be generated by evaluating a perimeter defense device through comparison of the different event flows. In some cases, various ones of the security devices may be inside or outside a perimeter defined by the perimeter defense device.
Information query
Patent Agency Ranking
0/0