Correlation engine system based on scene and data processing method thereof

An engine and scene technology, applied in the field of associated engine systems, can solve problems such as inability to dynamically load and expand, lack of scalability, and inability to effectively meet the ever-changing needs of the user's network environment.

CN101599958AInactive Publication Date: 2009-12-09XIDIAN UNIV
0 Cites 11 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Publication Date
2009-12-09
Estimated Expiration
Not applicable · inactive patent

Smart Images

  • Figure 1
    Figure 1
  • Figure 2
    Figure 2
  • Figure 3
    Figure 3
Patent Text Reader

Abstract

The invention discloses a correlation engine system based on scene and a data processing method thereof, aiming at mainly overcoming the disadvantages of poor expansibility and flexibility in the existing security management centers. The system is mainly composed of a plug-in module and a core module; wherein the plug-in module realizes different functions of the correlation engine system by configuring and installing an event format expanding plug-in, an event collecting plug-in, a scene analyzing plug-in and a response output plug-in; the core module describes the whole attack process as an attack scene changing states continuously by a management center, is in charge of correlation analysis and processing on warning information reported by each detection sensor, and realizes cooperative work and uniform management of all the sensors. The invention has the advantages of flexible configuration, easy expansibility and high detection rate and is applicable for data processing and analysis of various security management centers and intrusion detection systems.
Need to check novelty before this filing date? Find Prior Art

Description

technical field

[0001] The invention belongs to the technical field of computer security protection, in particular to a scenario-based correlation engine system for processing security data generated by network equipment including routers, switches, firewalls, intrusion detection systems and servers. Background technique

[0002] In recent years, the computer network has developed from being only a means of communication to a widely used computer environment infrastructure, especially the Internet, which has become an important network that governments, enterprises, financial institutions and thousands of users rely on. infrastructure.

[0003] At the same time, the security monitoring and management of this computer network has also become an important issue. For a long time, people have used intrusion detection system IDS products to solve this problem. IDS monitors information on the host system or the network, and searches for network packets, operating system calls, au...

Examples

Embodiment Construction

[0048] refer to figure 1 , the context-based correlation engine system of the present invention includes:

[0049] The core module is used to implement the logical analysis function of the correlation engine description language, record the current security status, collect and schedule security events, judge and trigger transition conditions, drive the transition of the current status, and based on the final transition status according to the input data information The processing result is given, which is the underlying implementation basis of the correlation engine and has nothing to do with specific applications;

[0050] The plug-in module is used to load different plug-ins for the core module, so that the correlation engine expands from an application-independent core module to a correlation engine with specific functions and detection of specific attacks, and realizes correlation by installing or upgrading plug-ins in the core module The upgrade and expansion of the engi...