SYSTEM AND METHOD OF AUTOMATIC INVESTIGATION OF SAFETY INCIDENTS IN AUTOMATED SYSTEM Russian patent published in 2018 - IPC G06F21/55 

Abstract RU 2664018 C1

FIELD: information technology.

SUBSTANCE: invention relates to information security systems. Automatic security incidents investigation system of an automated system contains means of loading data about system events from computer devices connected to the administration server; administration server that includes an event management tool for capturing, logging, analyzing at least one system event from the downloaded data that caused the security incident, and a solution search engine stored in memory and executed on the server of the administration server, the system including an analytical precedent description module for formalizing use cases, search for precedents in the database of precedents, updating of precedents, providing knowledge about the precedents, and precedents database that implements data representation and storage technology in ontology format.

EFFECT: technical result is to increase the effectiveness of automatic investigation of security incidents and, as a result, to reduce the response time to security incidents in an automated system.

2 cl, 2 dwg, 1 tbl

Similar patents RU2664018C1

Title Year Author Number
SYSTEM AND METHOD FOR PREDICTING SIGNS OF INFORMATION SECURITY INCIDENTS IN AUTOMATED CONTROL SYSTEMS 2023
  • Kozlov Denis Viktorovich
RU2815595C1
SYSTEM AND METHOD FOR AUTOMATIC INVESTIGATION OF SAFETY INCIDENTS 2011
  • Zajtsev Oleg Vladimirovich
RU2481633C2
METHOD AND SYSTEM OF CYBER TRAINING 2022
  • Bogdanov Vladimir Nikolaevich
  • Vikhlyantsev Petr Sergeevich
  • Anisimov Aleksandr Dmitrievich
  • Gerasimov Aleksandr Nikolaevich
  • Shmyrin Evgenij Aleksandrovich
  • Vikhlyantsev Aleksandr Petrovich
  • Serdyukov Nikolaj Nikolaevich
  • Kostyulin Ilya Nikolaevich
RU2808388C1
SYSTEM AND METHOD FOR PREVENTION SAFETY INCIDENTS BASED ON USER DANGER RATING 2011
  • Zajtsev Oleg Vladimirovich
  • Boronin Valerij Andreevich
RU2477929C2
METHOD FOR ADJUSTING THE PARAMETERS OF A MACHINE LEARNING MODEL IN ORDER TO IDENTIFY FALSE TRIGGERING AND INFORMATION SECURITY INCIDENTS 2020
  • Filonov Pavel Vladimirovich
  • Soldatov Sergej Vladimirovich
  • Udimov Daniil Alekseevich
RU2763115C1
METHOD FOR PROCESSING INFORMATION SECURITY EVENTS PRIOR TO TRANSMISSION FOR ANALYSIS 2020
  • Filonov Pavel Vladimirovich
  • Soldatov Sergej Vladimirovich
  • Udimov Daniil Alekseevich
RU2762528C1
SYSTEM AND METHOD OF RAISING SECURITY LEVEL OF COMPUTER SYSTEM 2011
  • Zajtsev Oleg Vladimirovich
  • Shevchenko Stanislav Borisovich
RU2460122C1
SYSTEM AND METHOD OF CORRELATING EVENTS FOR DETECTING INFORMATION SECURITY INCIDENT 2019
  • Lyukshin Ivan Stanislavovich
  • Kiryukhin Andrej Aleksandrovich
  • Lukiyan Dmitrij Sergeevich
  • Filonov Pavel Vladimirovich
RU2739864C1
METHOD OF COMPUTER SECURITY DISTRIBUTED EVENTS INVESTIGATION 2015
  • Gajnov Artur Evgenevich
  • Zavodtsev Ilya Valentinovich
RU2610395C1
SYSTEM AND METHOD OF DETECTING THE SIGNS OF COMPUTER ATTACKS 2017
  • Gordejchik Sergej Vladimirovich
  • Sapronov Konstantin Vladimirovich
  • Parshin Yurij Gennadevich
  • Kheirkhabarov Tejmur Samedovich
  • Soldatov Sergej Vladimirovich
RU2661533C1

RU 2 664 018 C1

Authors

Kozlov Denis Viktorovich

Dates

2018-08-14Published

2017-06-21Filed