×

Method of managing alerts issued by intrusion detection sensors of an information security system

  • US 7,810,157 B2
  • Filed: 12/16/2004
  • Issued: 10/05/2010
  • Est. Priority Date: 12/17/2003
  • Status: Expired due to Fees
First Claim
Patent Images

1. A method of managing alerts issued by intrusion detection sensors of an information security system including an alert management system, each alert being defined by an alert identifier and an alert content, the method comprising:

  • associating with each of the alerts issued by the intrusion detection sensors a description including a conjunction of valued attributes belonging to attribute domains;

    organizing the valued attributes belonging to each attribute domain into a taxonomic structure defining generalization relationships between said valued attributes, a plurality of attribute domains forming a plurality of taxonomic structures;

    completing the description of each of said alerts with sets of generalized valued attributes induced by the taxonomic structures based on the valued attributes of said alerts to form complete alerts;

    storing said complete alerts in a logic file system to enable said complete alerts to be consulted; and

    consulting the complete alerts by at least one of successively interrogating and browsing said complete alerts so that the alert management system responds to a request by supplying pertinent valued attributes enabling a subset of complete alerts to be distinguished in a set of complete alerts satisfying the request to enable said request to be refined, said request being a logic formula of at least one of said valued attributes;

    wherein each complete alert is saved in the logic file system as a file with a completed description of each complete alert expressed using propositional logic.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×