EP1700453A1 - PROCEDE DE GESTION D’UN ENSEMBLE D’ALERTES ISSUES DE SONDES DE DETECTION D'INTRUSIONS D'UN SYSTEME DE SECURITE D'INFORMATIONS. - Google Patents
PROCEDE DE GESTION D’UN ENSEMBLE D’ALERTES ISSUES DE SONDES DE DETECTION D'INTRUSIONS D'UN SYSTEME DE SECURITE D'INFORMATIONS.Info
- Publication number
- EP1700453A1 EP1700453A1 EP04816392A EP04816392A EP1700453A1 EP 1700453 A1 EP1700453 A1 EP 1700453A1 EP 04816392 A EP04816392 A EP 04816392A EP 04816392 A EP04816392 A EP 04816392A EP 1700453 A1 EP1700453 A1 EP 1700453A1
- Authority
- EP
- European Patent Office
- Prior art keywords
- alert
- alerts
- attribute
- description
- request
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Withdrawn
Links
- 238000000034 method Methods 0.000 title claims abstract description 25
- 239000000523 sample Substances 0.000 claims description 34
- 238000001514 detection method Methods 0.000 claims description 32
- 230000004044 response Effects 0.000 claims description 7
- 238000004590 computer program Methods 0.000 claims description 3
- 230000008569 process Effects 0.000 description 5
- 230000008520 organization Effects 0.000 description 3
- 230000021615 conjugation Effects 0.000 description 1
- 230000000694 effects Effects 0.000 description 1
- 230000007246 mechanism Effects 0.000 description 1
- 230000000306 recurrent effect Effects 0.000 description 1
- 238000011144 upstream manufacturing Methods 0.000 description 1
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1408—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
- H04L63/1425—Traffic logging, e.g. anomaly detection
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L43/00—Arrangements for monitoring or testing data switching networks
- H04L43/12—Network monitoring probes
Definitions
- the description of a given alert is supplemented by recovering from the generalization relationships of the plurality of taxonomic structures and recursively, a set comprising the more general value attributes and which has not already been present in the description of '' another alert previously completed.
- the attributes valued in the taxonomic structure are organized according to a directed acydic graph.
- the invention also relates to a computer program designed to implement the above method, when it is executed by the alert management system.
- the name of the organization corresponds to the "netname" field contained in the databases of the IANA TM organization, which manages the allocation of IP addresses.
- Internal IP addresses and private IP addresses (non-routable) can be generalized into local network identifiers defined by an administrator of the intrusion detection system 1.
- the names of organizations can be generalized to the value "ext" and the identifiers local networks can be generalized to the “int” value.
- the value attribute domain "victim" has IP addresses. These victims' IP addresses can be generalized to the address of the corresponding local network.
- These IP addresses can also be generalized into machine names, obtained by name resolution mechanisms. Machine names can be generalized into host “functions” (for example web server), defined by the site administrator.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
- Computer And Data Communications (AREA)
- Management, Administration, Business Operations System, And Electronic Commerce (AREA)
Abstract
Description
Claims
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| FR0314833A FR2864282A1 (fr) | 2003-12-17 | 2003-12-17 | Procede de gestion d'un ensemble d'alertes issus de sondes de detection d'intrusions d'un systeme de securite d'informations. |
| PCT/FR2004/003252 WO2005060205A1 (fr) | 2003-12-17 | 2004-12-16 | Procede de gestion d’un ensemble d’alertes issues de sondes de detection d’intrusions d’un systeme de securite d’informations. |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| EP1700453A1 true EP1700453A1 (fr) | 2006-09-13 |
Family
ID=34630264
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP04816392A Withdrawn EP1700453A1 (fr) | 2003-12-17 | 2004-12-16 | PROCEDE DE GESTION D’UN ENSEMBLE D’ALERTES ISSUES DE SONDES DE DETECTION D'INTRUSIONS D'UN SYSTEME DE SECURITE D'INFORMATIONS. |
Country Status (4)
| Country | Link |
|---|---|
| US (1) | US7810157B2 (fr) |
| EP (1) | EP1700453A1 (fr) |
| FR (1) | FR2864282A1 (fr) |
| WO (1) | WO2005060205A1 (fr) |
Families Citing this family (24)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US7376969B1 (en) | 2002-12-02 | 2008-05-20 | Arcsight, Inc. | Real time monitoring and analysis of events from multiple network security devices |
| US7219239B1 (en) | 2002-12-02 | 2007-05-15 | Arcsight, Inc. | Method for batching events for transmission by software agent |
| US7899901B1 (en) | 2002-12-02 | 2011-03-01 | Arcsight, Inc. | Method and apparatus for exercising and debugging correlations for network security system |
| US7650638B1 (en) | 2002-12-02 | 2010-01-19 | Arcsight, Inc. | Network security monitoring system employing bi-directional communication |
| US7607169B1 (en) | 2002-12-02 | 2009-10-20 | Arcsight, Inc. | User interface for network security console |
| US8176527B1 (en) | 2002-12-02 | 2012-05-08 | Hewlett-Packard Development Company, L. P. | Correlation engine with support for time-based rules |
| US7788722B1 (en) | 2002-12-02 | 2010-08-31 | Arcsight, Inc. | Modular agent for network security intrusion detection system |
| US7260844B1 (en) | 2003-09-03 | 2007-08-21 | Arcsight, Inc. | Threat detection in a network security system |
| US8015604B1 (en) | 2003-10-10 | 2011-09-06 | Arcsight Inc | Hierarchical architecture in a network security system |
| US9027120B1 (en) | 2003-10-10 | 2015-05-05 | Hewlett-Packard Development Company, L.P. | Hierarchical architecture in a network security system |
| US7565696B1 (en) | 2003-12-10 | 2009-07-21 | Arcsight, Inc. | Synchronizing network security devices within a network security system |
| US8528077B1 (en) | 2004-04-09 | 2013-09-03 | Hewlett-Packard Development Company, L.P. | Comparing events from multiple network security devices |
| US7509677B2 (en) | 2004-05-04 | 2009-03-24 | Arcsight, Inc. | Pattern discovery in a network security system |
| US7644438B1 (en) | 2004-10-27 | 2010-01-05 | Arcsight, Inc. | Security event aggregation at software agent |
| US9100422B1 (en) | 2004-10-27 | 2015-08-04 | Hewlett-Packard Development Company, L.P. | Network zone identification in a network security system |
| US7809131B1 (en) | 2004-12-23 | 2010-10-05 | Arcsight, Inc. | Adjusting sensor time in a network security system |
| US7647632B1 (en) | 2005-01-04 | 2010-01-12 | Arcsight, Inc. | Object reference in a system |
| US8850565B2 (en) * | 2005-01-10 | 2014-09-30 | Hewlett-Packard Development Company, L.P. | System and method for coordinating network incident response activities |
| US7844999B1 (en) | 2005-03-01 | 2010-11-30 | Arcsight, Inc. | Message parsing in a network security system |
| FR2888440A1 (fr) * | 2005-07-08 | 2007-01-12 | France Telecom | Procede et systeme de detection d'intrusions |
| CN101350745B (zh) * | 2008-08-15 | 2011-08-03 | 北京启明星辰信息技术股份有限公司 | 一种入侵检测方法及装置 |
| US8566947B1 (en) * | 2008-11-18 | 2013-10-22 | Symantec Corporation | Method and apparatus for managing an alert level for notifying a user as to threats to a computer |
| US9244713B1 (en) * | 2014-05-13 | 2016-01-26 | Nutanix, Inc. | Method and system for sorting and bucketizing alerts in a virtualization environment |
| US10313396B2 (en) * | 2016-11-15 | 2019-06-04 | Cisco Technology, Inc. | Routing and/or forwarding information driven subscription against global security policy data |
Family Cites Families (22)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| IT1275710B1 (it) * | 1995-03-31 | 1997-10-17 | Alcatel Italia | Metodo e sistema per la gestione dinamica in tempo reale della memorizzazione di errori di cui non si conoscano a priori quantita' |
| US6445774B1 (en) * | 1997-11-17 | 2002-09-03 | Mci Communications Corporation | System for automated workflow in a network management and operations system |
| US6393386B1 (en) * | 1998-03-26 | 2002-05-21 | Visual Networks Technologies, Inc. | Dynamic modeling of complex networks and prediction of impacts of faults therein |
| US6707795B1 (en) * | 1999-04-26 | 2004-03-16 | Nortel Networks Limited | Alarm correlation method and system |
| US7203962B1 (en) * | 1999-08-30 | 2007-04-10 | Symantec Corporation | System and method for using timestamps to detect attacks |
| US6647400B1 (en) * | 1999-08-30 | 2003-11-11 | Symantec Corporation | System and method for analyzing filesystems to detect intrusions |
| US7159237B2 (en) * | 2000-03-16 | 2007-01-02 | Counterpane Internet Security, Inc. | Method and system for dynamic network intrusion monitoring, detection and response |
| GB2361382A (en) * | 2000-04-12 | 2001-10-17 | Mitel Corp | Tree hierarchy and description for generated logs |
| CA2313908A1 (fr) * | 2000-07-14 | 2002-01-14 | David B. Skillicorn | Detection d'intrusion dans des reseaux faisant appel a la decomposition en valeurs singulieres |
| US6732153B1 (en) * | 2000-05-23 | 2004-05-04 | Verizon Laboratories Inc. | Unified message parser apparatus and system for real-time event correlation |
| US7143442B2 (en) * | 2000-08-11 | 2006-11-28 | British Telecommunications | System and method of detecting events |
| AU2001295016A1 (en) * | 2000-09-01 | 2002-03-13 | Sri International, Inc. | Probabilistic alert correlation |
| GB0022485D0 (en) * | 2000-09-13 | 2000-11-01 | Apl Financial Services Oversea | Monitoring network activity |
| US7379993B2 (en) * | 2001-09-13 | 2008-05-27 | Sri International | Prioritizing Bayes network alerts |
| US7437762B2 (en) * | 2001-11-29 | 2008-10-14 | International Business Machines Corporation | Method, computer program element and a system for processing alarms triggered by a monitoring system |
| US20030101260A1 (en) * | 2001-11-29 | 2003-05-29 | International Business Machines Corporation | Method, computer program element and system for processing alarms triggered by a monitoring system |
| US6801940B1 (en) * | 2002-01-10 | 2004-10-05 | Networks Associates Technology, Inc. | Application performance monitoring expert |
| US7026926B1 (en) * | 2002-08-15 | 2006-04-11 | Walker Iii Ethan A | System and method for wireless transmission of security alarms to selected groups |
| EP1535164B1 (fr) * | 2002-08-26 | 2012-01-04 | International Business Machines Corporation | Determination du niveau de menace associe a l'activite d'un reseau |
| KR100456634B1 (ko) * | 2002-10-31 | 2004-11-10 | 한국전자통신연구원 | 정책기반 침입 탐지 및 대응을 위한 경보 전달 장치 및 방법 |
| US7712133B2 (en) * | 2003-06-20 | 2010-05-04 | Hewlett-Packard Development Company, L.P. | Integrated intrusion detection system and method |
| US20050086529A1 (en) * | 2003-10-21 | 2005-04-21 | Yair Buchsbaum | Detection of misuse or abuse of data by authorized access to database |
-
2003
- 2003-12-17 FR FR0314833A patent/FR2864282A1/fr not_active Withdrawn
-
2004
- 2004-12-16 US US10/583,586 patent/US7810157B2/en not_active Expired - Fee Related
- 2004-12-16 EP EP04816392A patent/EP1700453A1/fr not_active Withdrawn
- 2004-12-16 WO PCT/FR2004/003252 patent/WO2005060205A1/fr not_active Ceased
Non-Patent Citations (1)
| Title |
|---|
| See references of WO2005060205A1 * |
Also Published As
| Publication number | Publication date |
|---|---|
| US20070150579A1 (en) | 2007-06-28 |
| FR2864282A1 (fr) | 2005-06-24 |
| WO2005060205A1 (fr) | 2005-06-30 |
| US7810157B2 (en) | 2010-10-05 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| EP1700453A1 (fr) | PROCEDE DE GESTION D’UN ENSEMBLE D’ALERTES ISSUES DE SONDES DE DETECTION D'INTRUSIONS D'UN SYSTEME DE SECURITE D'INFORMATIONS. | |
| US20250330375A1 (en) | Graphical user interface representing event streams | |
| US7240049B2 (en) | Systems and methods for search query processing using trend analysis | |
| EP1695485B1 (fr) | Procede de classification automatique d un ensemble d a lertes issues de sondes de detection d intrusions d un systeme de securite d information | |
| US10367827B2 (en) | Using network locations obtained from multiple threat lists to evaluate network data or machine data | |
| US8527486B2 (en) | Mobile application discovery through mobile search | |
| US12181956B1 (en) | Machine-learning based prioritization of alert groupings | |
| US20190124104A1 (en) | Graph-Based Network Anomaly Detection Across Time and Entities | |
| Thelwall | Extracting accurate and complete results from search engines: Case study Windows Live | |
| US20250193218A1 (en) | Systems and methods of malware detection | |
| US20080228695A1 (en) | Techniques for analyzing and presenting information in an event-based data aggregation system | |
| Al-Saggaf et al. | Data mining and privacy of social network sites’ users: implications of the data mining problem | |
| US11552974B1 (en) | Cybersecurity risk analysis and mitigation | |
| US12066915B1 (en) | Systems and methods for retraining machine-learning models to perform alert grouping | |
| Hunn et al. | How to implement online warnings to prevent the use of child sexual abuse material | |
| HK1198781A1 (en) | System to identify multiple copyright infringements | |
| Zeng et al. | Semantic IoT data description and discovery in the IoT-edge-fog-cloud infrastructure | |
| Spangher et al. | Characterizing search-engine traffic to internet research agency web properties | |
| Thomas | To what problem is distributed information retrieval the solution? | |
| Buntain et al. | # pray4victims: Consistencies in Response to Disaster on Twitter | |
| CN110222156B (zh) | 发现实体的方法和装置、电子设备、计算机可读介质 | |
| CA2921758A1 (fr) | Scripts automatises d'extraction et d'indexation d'information avec analyseur de paquets | |
| Aghamohammadi | A novel defense mechanism against web crawler intrusion | |
| Barredo-Valenzuela et al. | Snorkeling in dark waters: A longitudinal surface exploration of unique Tor Hidden Services (Extended Version) | |
| KR20240015280A (ko) | 트렌드 분석을 이용한 검색 쿼리 처리 시스템 및 방법 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| 17P | Request for examination filed |
Effective date: 20060712 |
|
| AK | Designated contracting states |
Kind code of ref document: A1 Designated state(s): AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HU IE IS IT LI LT LU MC NL PL PT RO SE SI SK TR |
|
| RIN1 | Information on inventor provided before grant (corrected) |
Inventor name: DEBAR, HERVE Inventor name: MORIN, BENJAMIN |
|
| DAX | Request for extension of the european patent (deleted) | ||
| GRAP | Despatch of communication of intention to grant a patent |
Free format text: ORIGINAL CODE: EPIDOSNIGR1 |
|
| RIC1 | Information provided on ipc code assigned before grant |
Ipc: H04L 12/26 20060101AFI20111125BHEP Ipc: H04L 29/06 20060101ALI20111125BHEP Ipc: G06F 17/30 20060101ALI20111125BHEP |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE APPLICATION IS DEEMED TO BE WITHDRAWN |
|
| 18D | Application deemed to be withdrawn |
Effective date: 20120508 |