×

Log analysis system, method and apparatus

  • US 20060259968A1
  • Filed: 11/14/2005
  • Published: 11/16/2006
  • Est. Priority Date: 05/12/2005
  • Status: Active Grant
First Claim
Patent Images

1. A log analysis system for analyzing a state of incidents occurred in a network and comprising a security unit connected to the network, a collection unit connected to the security unit and an analysis unit connected to the collection unit;

  • the security unit including detection means for detecting illegal packets flowing in the network and first transmission means for transmitting event information concerning the packets to the collection unit when illegal packets are detected;

    the collection unit including event database storage means for obtaining the event information from the security unit to be stored therein, first search means for receiving from the analysis unit an event obtainment request message for obtaining events occurred in a specified period and coincident with specified conditions to search the event database for the events having the specified conditions, and second transmission means for transmitting the searched events to the analysis unit;

    the analysis unit including third transmission means for transmitting the event obtainment request message to the collection unit, analysis means for analyzing the event information obtained from the collection unit in response to the event obtainment request message, analysis database means for storing information of the analyzed result, event statistical information preparation means for preparing event statistical information on the basis of the obtained event information, frequency component information preparation means for subjecting the prepared event statistical information to frequency analysis processing to prepare frequency component information including frequency information and strength information, and decision means for making analysis on the basis of the frequency component to judge occurrence tendency of incidents.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×