Invention Grant
- Patent Title: Security incident manager
- Patent Title (中): 安全事故经理
-
Application No.: US11489707Application Date: 2006-07-18
-
Publication No.: US08209759B2Publication Date: 2012-06-26
- Inventor: Christopher D. Newton , William Bird
- Applicant: Christopher D. Newton , William Bird
- Applicant Address: US MA Waltham
- Assignee: Q1 Labs, Inc.
- Current Assignee: Q1 Labs, Inc.
- Current Assignee Address: US MA Waltham
- Agency: Goodwin Procter LLP
- Main IPC: G06F11/00
- IPC: G06F11/00 ; G06F12/14

Abstract:
A security incident manger includes events and network flows in the analysis of an attack to better identify the magnitude of the attack and how to handle the situation. The raw events are reported by monitored devices and the incident manager may request network flows from various devices corresponding to a raw event. The manager then assigns a variable score to the severity, the relevance and the credibility of the event to determine its next processing steps. Those events that appear to be a likely and effective attack are classified as offenses. Offenses are stored in order to provide additional data for evaluating future events and for building a “rap sheet” against repeat attackers and repeat events.
Public/Granted literature
- US20070180107A1 Security incident manager Public/Granted day:2007-08-02
Information query