Unlock instant, AI-driven research and patent intelligence for your innovation.

Method and device for detecting security event

A security event and detection method technology, applied in the field of communication, can solve problems such as low detection efficiency, large calculation amount, and increased calculation amount, and achieve the effects of reducing calculation amount, improving detection efficiency, and ensuring real-time performance

Inactive Publication Date: 2013-01-30
HUAWEI DIGITAL TECH (CHENGDU) CO LTD
View PDF3 Cites 0 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

[0004] In the process of realizing the present invention, the inventors found that there are at least the following problems in the prior art: the rule association method based on security event modeling and the association method based on causality completely rely on pre-established association rules for matching, and can only Detecting known types of security events, the detection efficiency is not high, and the feature description library must be continuously updated. At the same time, because all the collected information needs to be matched with the pre-established association rules, the increasingly large association rules make the calculation amount The increase affects the real-time performance of security event detection; the clustering correlation method adopts statistical methods for processing, and the results often lack clear practical significance, and some events can only be classified into one category, but cannot be described The characteristics of this type of event make it impossible to perform subsequent response processing, and because all the collected information needs to be clustered, the amount of calculation is larger, which affects the real-time performance of security event detection

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Method and device for detecting security event
  • Method and device for detecting security event
  • Method and device for detecting security event

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0029] The technical solutions in the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the present invention. Obviously, the described embodiments are only some of the embodiments of the present invention, not all of them. Based on the embodiments of the present invention, all other embodiments obtained by persons of ordinary skill in the art without making creative efforts belong to the protection scope of the present invention.

[0030] The technical solutions of the embodiments of the present invention will be described in further detail below with reference to the drawings and embodiments.

[0031] figure 1 It is a flow chart of the first embodiment of the security event detection method of the present invention. like figure 1 As shown, the embodiment of the present invention provides a security event detection method, including:

[0032] Step 101, obtaining the probability of occurrence of the current e...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

PUM

No PUM Login to View More

Abstract

The embodiment of the invention discloses a method and a device for detecting a security event. The method comprises the following steps: acquiring the occurrence probability of the current even; whenthe occurrence probability of the current event is smaller than a preset threshold value, carrying out rule matching on the current event according to an associated rule base; if the matching is successful, confirming that the current event is a known security event; and otherwise, confirming that the current event is an unknown security event. The device comprises an acquiring module and a matching module. The embodiment of the invention reduces the operation amount by just carrying out the rule matching on the event with the probability smaller than the preset threshold value, thereby ensuring the detecting instantaneity of the security event and improving the defecting efficiency.

Description

technical field [0001] The present invention relates to the communication field, in particular to a security event detection method and device. Background technique [0002] With the continuous development and popularization of information technology, the problem of information security is becoming more and more serious. In computer networks, the number of security incidents such as malicious attacks, illegal intrusions, virus Trojan horses, information leaks, sudden failures, and traffic anomalies is increasing exponentially. Security incidents pose a serious threat to computer network systems, and it is necessary to take effective measures to prevent, monitor, and deal with various security incidents to ensure the normal operation of the system. The detection of security incidents is an essential link, and the purpose of detecting security incidents is to carry out subsequent operations such as alarming and responding to security incidents. [0003] The existing security...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

Application Information

Patent Timeline
no application Login to View More
Patent Type & Authority Patents(China)
IPC IPC(8): H04L29/06H04L12/24
Inventor 王飞覃健诚朱洪亮
Owner HUAWEI DIGITAL TECH (CHENGDU) CO LTD