×

SECURITY EVENT MONITORING DEVICE, METHOD, AND PROGRAM

  • US 20130067572A1
  • Filed: 09/10/2012
  • Published: 03/14/2013
  • Est. Priority Date: 09/13/2011
  • Status: Abandoned Application
First Claim
Patent Images

1. A security event monitoring device which detects a specific operation from logs that are records of operations conducted on a plurality of monitoring target devices connected mutually on a same local network, the security event monitoring device comprising:

  • a storage module which stores in advance a correlation rule that is applied when performing a correlation analysis on each of the logs;

    a log collection unit which receives each of the logs from each of the monitoring target devices;

    a correlation analysis unit which generates scenario candidates in which each of the logs is associated with each other by applying the correlation rule to each of the logs, and stores the scenario candidates to the storage module along with an importance degree of the scenario candidate given by the correlation rule;

    a scenario candidate evaluation unit which recalculates the importance degree for each of the scenario candidates; and

    a result display unit which displays/outputs the scenario candidate with the recalculated high importance degree, whereinthe scenario candidate evaluation unit comprises;

    a user association degree evaluation function which enumerates possible users who may have done each of the operations contained in each of the scenario candidates, and calculates user association degrees that are relevancies of each of the users for each of the operations;

    an operation association degree evaluation function which calculates operation association degrees that are relevancies between each of the operations of each of the scenario candidates; and

    a scenario candidate importance degree reevaluation function which recalculates the importance degrees of each of the scenario candidates by each of the users according to the user association degrees and the operation association degrees.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×