×

Hierarchical correlation of intrusion detection events

  • US 20030046582A1
  • Filed: 08/30/2001
  • Published: 03/06/2003
  • Est. Priority Date: 08/30/2001
  • Status: Active Grant
First Claim
Patent Images

1. A method in a data processing system for reporting security situations, comprising the steps of:

  • logging events by storing event attributes as an event set, wherein each event set includes a source attribute, a target attribute and an event category attribute;

    classifying events as groups by aggregating events with at least one attribute within the event set as an identical value;

    calculating severity levels for the groups;

    calculating delta severities from the severity levels; and

    propagating the delta severities to a higher-level correlation server.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×