Invention Grant
US08776241B2 Automatic analysis of security related incidents in computer networks
有权
自动分析计算机网络中的安全相关事件
- Patent Title: Automatic analysis of security related incidents in computer networks
- Patent Title (中): 自动分析计算机网络中的安全相关事件
-
Application No.: US13219887Application Date: 2011-08-29
-
Publication No.: US08776241B2Publication Date: 2014-07-08
- Inventor: Oleg Zaitsev
- Applicant: Oleg Zaitsev
- Applicant Address: RU Moscow
- Assignee: Kaspersky Lab ZAO
- Current Assignee: Kaspersky Lab ZAO
- Current Assignee Address: RU Moscow
- Agency: Patterson Thuente Pedersen, PA
- Main IPC: H04L29/06
- IPC: H04L29/06

Abstract:
Solutions for responding to security-related incidents in a computer network, including a security server, and a client-side arrangement. The security server includes an event collection module communicatively coupled to the computer network, an event analysis module operatively coupled to the event collection module, and a solution module operatively coupled to the event analysis module. The event collection module is configured to obtain incident-related information that includes event-level information from at least one client computer of the plurality of client computers, the incident-related information being associated with at least a first incident which was detected by that at least one client computer and provided to the event collection module in response to that detection. The event analysis module is configured to reconstruct at least one chain of events causally related to the first incident and indicative of a root cause of the first incident based on the incident-related information. The solution module is configured to formulate at least one recommendation for use by the at least one client computer, the at least one recommendation being based on the at least one chain of events, and including corrective/preventive action particularized for responding to the first incident.
Public/Granted literature
- US20130055399A1 AUTOMATIC ANALYSIS OF SECURITY RELATED INCIDENTS IN COMPUTER NETWORKS Public/Granted day:2013-02-28
Information query