首页> 外国专利> Method and Apparatus for executing proof collection and investigation analysis for incident response

Method and Apparatus for executing proof collection and investigation analysis for incident response

机译:对事件响应进行证据收集和调查分析的方法和装置

摘要

The present invention relates to a hacking response technology. More specifically, the present invention relates to a method and an apparatus for automatically performing evidence collection and investigation analysis on an infringement incident. According to the present invention, by automatically collecting evidence, data randomly deleted by an attacker or missed by a log limited capacity can be minimized. The method comprises the following steps: a data collection unit collects data; an information generation unit stores extracted information by parsing the collected data, and extracting information; an analysis identification module identifies behavior events by using the extracted information; the analysis identification module identifies a corresponding event related to inflow, execution, and transmission of a malicious code in a host among the identified behavior events; and the analysis identification module identifies an access point, and a moving and transmitting path of the malicious code to the inside of a domain by using the corresponding behavior event.
机译:本发明涉及黑客响应技术。更具体地,本发明涉及一种用于对侵权事件自动进行证据收集和调查分析的方法和设备。根据本发明,通过自动收集证据,可以最小化被攻击者随机删除或被日志限制容量遗漏的数据。该方法包括以下步骤:数据收集单元收集数据;信息生成单元通过解析收集的数据并提取信息来存储提取的信息;分析识别模块通过使用提取的信息来识别行为事件;分析识别模块,在识别出的行为事件中,识别与主机中恶意代码的流入,执行和传输相关的事件;分析识别模块通过使用相应的行为事件来识别访问点以及恶意代码到域内部的移动和传输路径。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号