컴퓨터 네트워크 보안을 보조하기 위한 자산 모델의 실시간식별 및 자산의 카테고리화
    1.
    发明公开
    컴퓨터 네트워크 보안을 보조하기 위한 자산 모델의 실시간식별 및 자산의 카테고리화 有权
    资产模型的实时识别和资产分类以协助计算机网络安全

    公开(公告)号:KR1020090061627A

    公开(公告)日:2009-06-16

    申请号:KR1020097004992

    申请日:2007-10-25

    Abstract: unique identifier is assigned to a network node and is used to obtain an "asset model" corresponding to the node and to determine whether the node is a member of a particular category. An asset model is a set of information about a node (e.g., the node's role within the enterprise, software installed on the node, and known vulnerabilities/weaknesses of the node). An identifier lookup module determines a node's identifier based on characteristics of the node (such as [P address., host name, network zone, and/or MAC address), which are used as keys into lookup data structures. A category lookup module determines whether a particular node is a member of (i.e., within) a particular category using a transitive closure to model the categories (properties) that can be attached to an asset model. A transitive closure for a particular asset category is stored as a bitmap, similar to bitmap indexing.

    Abstract translation: 将唯一标识符分配给网络节点,并用于获得与节点对应的“资产模型”,并确定该节点是否是特定类别的成员。 资产模型是关于节点的一组信息(例如,节点在企业内的角色,安装在节点上的软件以及节点的已知漏洞/弱点)。 标识符查找模块基于用作查找数据结构中的键的节点的特征(例如[P地址,主机名,网络区域和/或MAC地址])来确定节点的标识符。 类别查找模块使用传递闭包来确定特定节点是否是特定类别的成员(即,在特定类别之内),以模拟可附加到资产模型的类别(属性)。 特定资产类别的传递闭包存储为位图,类似于位图索引。

    컴퓨터 네트워크 보안을 보조하기 위한, 로그 데이터의 효과적인 저장과 질의의 지원
    4.
    发明公开
    컴퓨터 네트워크 보안을 보조하기 위한, 로그 데이터의 효과적인 저장과 질의의 지원 有权
    在计算机网络安全的情况下有效地存储日志数据

    公开(公告)号:KR1020090100344A

    公开(公告)日:2009-09-23

    申请号:KR1020097011683

    申请日:2007-12-28

    Abstract: A logging system includes an event receiver and a storage manager. The receiver receives log data, processes it, and outputs a data ''chunk.'' The manager receives data chunks and stores them so that they can be queried. The receiver includes buffers that store events and a metadata structure that stores metadata about the contents of the buffers. The metadata includes a unique identifier associated with the receiver, the number of events in the buffers, and, for each ''field of interest,'' a minimum value and a maximum value that reflect the range of values of that field over all of the events in the buffers. A chunk includes the metadata structure and a compressed version of the contents of the buffers. The metadata structure acts as a search index when querying event data. The logging system can be used in conjunction with a security information/event management (SIEM) system.

    Abstract translation: 记录系统包括事件接收器和存储管理器。 接收器接收日志数据,处理它,并输出数据“块”。管理器接收数据块并存储它们,以便可以查询。 接收器包括存储事件的缓冲器和存储关于缓冲器的内容的元数据的元数据结构。 元数据包括与接收器相关联的唯一标识符,缓冲器中的事件数量,以及针对每个“感兴趣的领域”的最小值和最大值,其反映该字段的值的范围 缓冲区中的事件。 块包括元数据结构和缓冲区内容的压缩版本。 元数据结构在查询事件数据时用作搜索索引。 记录系统可以与安全信息/事件管理(SIEM)系统结合使用。

Patent Agency Ranking