Method of managing alerts issued by intrusion detection sensors of an information security system
First Claim
1. A method of managing alerts issued by intrusion detection sensors of an information security system including an alert management system, each alert being defined by an alert identifier and an alert content, the method comprising:
- associating with each of the alerts issued by the intrusion detection sensors a description including a conjunction of valued attributes belonging to attribute domains;
organizing the valued attributes belonging to each attribute domain into a taxonomic structure defining generalization relationships between said valued attributes, a plurality of attribute domains forming a plurality of taxonomic structures;
completing the description of each of said alerts with sets of generalized valued attributes induced by the taxonomic structures based on the valued attributes of said alerts to form complete alerts;
storing said complete alerts in a logic file system to enable said complete alerts to be consulted; and
consulting the complete alerts by at least one of successively interrogating and browsing said complete alerts so that the alert management system responds to a request by supplying pertinent valued attributes enabling a subset of complete alerts to be distinguished in a set of complete alerts satisfying the request to enable said request to be refined, said request being a logic formula of at least one of said valued attributes;
wherein each complete alert is saved in the logic file system as a file with a completed description of each complete alert expressed using propositional logic.
1 Assignment
0 Petitions
Accused Products
Abstract
A method of managing alerts issued by intrusion detection sensors (11a, 11b, 11c) of an information security system (1) including an alert management system (13), each alert being defined by an alert identifier and an alert content. Each of the alerts issued by the intrusion detection sensors (11a, 11b, 11c) is associated with a description including a conjunction of valued attributes belonging to attribute domains. The valued attributes belonging to each attribute domain are organized into a taxonomic structure defining generalization relationships between said valued attributes, the plurality of attribute domains thus forming a plurality of taxonomic structures. The description of each of said alerts is completed with sets of values induced by the taxonomic structures on the basis of the valued attributes of said alerts to form complete alerts. The complete alerts are stored in a logic file system (21) to enable them to be consulted.
-
Citations
11 Claims
-
1. A method of managing alerts issued by intrusion detection sensors of an information security system including an alert management system, each alert being defined by an alert identifier and an alert content, the method comprising:
-
associating with each of the alerts issued by the intrusion detection sensors a description including a conjunction of valued attributes belonging to attribute domains; organizing the valued attributes belonging to each attribute domain into a taxonomic structure defining generalization relationships between said valued attributes, a plurality of attribute domains forming a plurality of taxonomic structures; completing the description of each of said alerts with sets of generalized valued attributes induced by the taxonomic structures based on the valued attributes of said alerts to form complete alerts; storing said complete alerts in a logic file system to enable said complete alerts to be consulted; and consulting the complete alerts by at least one of successively interrogating and browsing said complete alerts so that the alert management system responds to a request by supplying pertinent valued attributes enabling a subset of complete alerts to be distinguished in a set of complete alerts satisfying the request to enable said request to be refined, said request being a logic formula of at least one of said valued attributes; wherein each complete alert is saved in the logic file system as a file with a completed description of each complete alert expressed using propositional logic. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9)
-
-
10. Alert management system for managing alerts issued by intrusion detection sensors, each alert being defined by an alert identifier and an alert content, the system comprising:
-
processor means for associating with each of the alerts issued by the intrusion detection sensors a description including a conjunction of valued attributes belonging to attribute domains; processor means for organizing the valued attributes belonging to each attribute domain into a taxonomic structure defining generalization relationships between said valued attributes, a plurality of attribute domains forming a plurality of taxonomic structures; processor means for completing the description of each of said alerts with sets of generalized valued attributes induced by the taxonomic structures based on the valued attributes of said alerts to form complete alerts; processor means for storing said complete alerts in a logic file system to enable said complete alerts to be consulted; and processor means for consulting the complete alerts by at least one of successively interrogating and browsing said complete alerts so that the alert management system responds to a request by supplying pertinent valued attributes enabling a subset of complete alerts to be distinguished in a set of complete alerts satisfying the request to enable said request to be refined, said request being a logic formula of at least one of said valued attributes; wherein each complete alert is saved in the logic file system as a file with a completed description of each complete alert expressed using propositional logic. - View Dependent Claims (11)
-
Specification