Inventors:
Kumar Saurabh - Santa Clara CA, US
Kenny Tidwell - Los Altos CA, US
Assignee:
ArcSight, Inc. - Cupertino CA
International Classification:
G06F 7/04
H04L 9/32
G06F 17/30
G06F 11/30
US Classification:
726 23, 726 22, 726 24, 726 25, 726 26, 726 27, 726 3, 726 4, 726 5, 726 6, 726 7, 713182, 713188, 709223, 709224, 709225, 709226, 709227
Abstract:
Patterns can be discovered in security events collected by a network security system. In one embodiment, the present invention includes collecting and storing security events from a variety of monitor devices. In one embodiment, a subset of the stored security events is provided to a manager as an event stream. In one embodiment, the present invention further includes the manager discovering one or more previously unknown event patterns in the event stream.