×

Semantically-aware behavioral security analysis system for security information and event management

  • US 9,064,210 B1
  • Filed: 03/31/2012
  • Issued: 06/23/2015
  • Est. Priority Date: 03/31/2012
  • Status: Active Grant
First Claim
Patent Images

1. An apparatus comprising:

  • at least one processing device comprising a processor coupled to a memory and implementing a behavioral security analysis system, the behavioral security analysis system comprising;

    a computational semantic parser configured to process data associated with a security information and event management system to generate a plurality of logical descriptors, the data comprising log data of the security information and event management system; and

    a learning engine coupled to the computational semantic parser and configured to generate a plurality of behavioral security descriptors based at least in part on at least a subset of the logical descriptors;

    wherein the behavioral security descriptors are made accessible to an alerting engine of the security information and event management system and utilized to generate one or more security alerts; and

    wherein the computational semantic parser comprises;

    a syntactic decomposition module configured to decompose at least a portion of the log data into component elements comprising respective atomic syntactic units;

    a lexical meaning assignment module configured to assign lexical meanings to the component elements utilizing metadata associated with the component elements and a lexicon of syntactic types, the metadata comprising position information and attributes associated with the atomic syntactic units;

    a denotation assignment module configured to assign context denotation information to the component elements; and

    a semantic recomposition module configured to generate a given logical descriptor based on at least one combinatorial tree having nodes associated with respective ones of the component elements and a tree structure determined using the assigned lexical meanings and context denotation information.

View all claims
  • 9 Assignments
Timeline View
Assignment View
    ×
    ×