METHOD AND SYSTEM FOR ELIMINATING DUPLICATE CORRELATION CHAINS OF EVENTS WHEN DETECTING INFORMATION SECURITY INCIDENTS Russian patent published in 2025 - IPC G06F21/55 

Abstract RU 2834858 C1

FIELD: computer engineering.

SUBSTANCE: method of eliminating duplicate correlation chains of events when detecting information security incidents includes steps of: obtaining information from computers in a network; generating an attribute-containing event based on the received information; determining the created correlation chain, wherein for the first event of each determined correlation chain, fixing the attributes based on the corresponding correlation rule; comparing the generated event with the first event from each determined correlation chain, during which the similarity of attributes is determined; if the correlation chain complies with the correlation rule, an information security incident is detected.

EFFECT: reduction of false positives when detecting information security incidents.

14 cl, 6 dwg

Similar patents RU2834858C1

Title Year Author Number
SYSTEM AND METHOD OF CORRELATING EVENTS FOR DETECTING INFORMATION SECURITY INCIDENT 2019
  • Lyukshin Ivan Stanislavovich
  • Kiryukhin Andrej Aleksandrovich
  • Lukiyan Dmitrij Sergeevich
  • Filonov Pavel Vladimirovich
RU2739864C1
METHOD OF COMPUTER SECURITY DISTRIBUTED EVENTS INVESTIGATION 2015
  • Gajnov Artur Evgenevich
  • Zavodtsev Ilya Valentinovich
RU2610395C1
SYSTEM AND METHOD FOR PREDICTING SIGNS OF INFORMATION SECURITY INCIDENTS IN AUTOMATED CONTROL SYSTEMS 2023
  • Kozlov Denis Viktorovich
RU2815595C1
METHOD FOR FAST FILTERING OF DATA SETS ON COMPUTER INCIDENTS OF INFORMATION SECURITY 2023
  • Matveev Lev Lazarevich
RU2828162C1
METHOD FOR FILTERING EVENTS FOR TRANSMISSION TO REMOTE DEVICE 2022
  • Pintiiskii Vladislav Valerevich
  • Tarakanov Dmitrii Vladimirovich
  • Shulmin Aleksei Sergeevich
  • Ovcharik Vladislav Ivanovich
  • Kuskov Vladimir Anatolevich
RU2813239C1
SYSTEM AND METHOD FOR AUTOMATIC INVESTIGATION OF SAFETY INCIDENTS 2011
  • Zajtsev Oleg Vladimirovich
RU2481633C2
INFORMATION SECURITY INCIDENT RESPONSE SYSTEM AND METHOD 2023
  • Zaitsev Oleg Vladimirovich
RU2824732C1
METHOD AND SYSTEM OF TCP SESSION DATA COLLECTION BETWEEN PARTICIPANTS 2024
  • Liukshin Ivan Stanislavovich
RU2833442C1
METHOD FOR ADJUSTING THE PARAMETERS OF A MACHINE LEARNING MODEL IN ORDER TO IDENTIFY FALSE TRIGGERING AND INFORMATION SECURITY INCIDENTS 2020
  • Filonov Pavel Vladimirovich
  • Soldatov Sergej Vladimirovich
  • Udimov Daniil Alekseevich
RU2763115C1
METHOD FOR GENERATING THE SIGNATURE OF AN UNWANTED ELECTRONIC MESSAGE 2021
  • Marchenko Aleksei Sergeevich
  • Utki-Otki Aleksei Evgenevich
  • Golubev Dmitrii Sergeevich
  • Slobodianiuk Iurii Gennadevich
RU2776924C1

RU 2 834 858 C1

Authors

Liukshin Ivan Stanislavovich

Dates

2025-02-14Published

2024-04-19Filed