首页> 外国专利> Incident response bus for data security incidents

Incident response bus for data security incidents

机译:用于数据安全事件的事件响应总线

摘要

A system and method for responding to data security incidents in enterprise networks using an incident response bus (IR bus) within an incident management system is disclosed. An Incident Manager (IM) application of the system stores objects that include information concerning data security incidents that occur in enterprise networks managed by the incident management system. Users configure action conditions on the IM, the satisfaction of which cause the IM to send messages that include the information concerning the incidents to message queues, or destinations. Correspondingly, the IR bus includes plugins associated with the devices in each client's enterprise network, where each plugin can access the message destinations for the messages. The plugins, in one embodiment, also configure one or more chains of plugins that process the messages. The plugins then execute the chains of plugins to specify actions for the devices to execute to provide a response to the incidents.
机译:公开了一种用于使用事件管理系统内的事件响应总线(IR总线)来响应企业网络中的数据安全事件的系统和方法。系统的事件管理器(IM)应用程序存储对象,这些对象包括有关由事件管理系统管理的企业网络中发生的数据安全事件的信息。用户在IM上配置操作条件,对此条件的满足会导致IM向消息队列或目的地发送包含与事件有关的信息的消息。相应地,IR总线包括与每个客户端的企业网络中的设备关联的插件,每个插件都可以在其中访问消息的消息目标。在一个实施例中,插件还配置了一个或多个处理消息的插件链。然后,插件执行插件链,以指定设备要执行的操作以提供对事件的响应。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号