会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 3. 发明申请
    • NETWORK SECURITY INVESTIGATION WORKFLOW LOGGING
    • 网络安全调查工作流记录
    • US20170031565A1
    • 2017-02-02
    • US14815984
    • 2015-08-01
    • Splunk Inc.
    • Vijay ChauhanCary NoelWenhui YuLuke Murphey
    • G06F3/0484H04L29/06
    • G06F3/04842G06F3/04847H04L63/1416H04L63/1425
    • Techniques and mechanisms are disclosed that enable network security analysts and other users to efficiently conduct network security investigations and to produce useful representations of investigation results. As used herein, a network security investigation generally refers to an analysis by an analyst (or team of analysts) of one or more detected network events that may pose internal and/or external threats to a computer network under management. A network security application provides various interfaces that enable users to create investigation timelines, where the investigation timelines display a collection of events related to a particular network security investigation. A network security application further provides functionality to monitor and log user interactions with the network security application, where particular logged user interactions may also be added to one or more investigation timelines.
    • 公开了技术和机制,使网络安全分析师和其他用户有效地进行网络安全调查并产生调查结果的有用表示。 如本文所使用的,网络安全调查通常是指分析者(或分析师小组)对可能对管理的计算机网络造成内部和/或外部威胁的一个或多个检测到的网络事件的分析。 网络安全应用程序提供各种接口,使用户能够创建调查时间表,其中调查时间表显示与特定网络安全调查相关的事件的集合。 网络安全应用程序还提供监视和记录与网络安全应用程序的用户交互的功能,其中特定记录的用户交互也可以被添加到一个或多个调查时间线。
    • 4. 发明授权
    • Multi-lane time-synched visualizations of machine data events
    • 机器数据事件的多通道时间同步可视化
    • US08806361B1
    • 2014-08-12
    • US14046767
    • 2013-10-04
    • Splunk Inc.
    • Cary NoelJohn Coates
    • G06F3/048G06F3/0482
    • G06F3/0481G06F3/0484G06F3/04842G06F17/30551G06F17/30554
    • A visualization can include a set of swim lanes, each swim lane representing information about an event type. An event type can be specified, e.g., as those events having certain keywords and/or having specified value(s) for specified field(s). The swim lane can plot when (within a time range) events of the associated event type occurred. Specifically, each such event can be assigned to a bucket having a bucket time matching the event time. A swim lane can extend along a timeline axis in the visualization, and the buckets can be positioned at a point along the axis that represents the bucket time. Thus, the visualization may indicate whether events were clustered at a point in time. Because the visualization can include a plurality of swim lanes, the visualization can further indicate how timing of events of a first type compare to timing of events of a second type.
    • 可视化可以包括一组泳道,每个泳道表示关于事件类型的信息。 可以指定事件类型,例如作为具有某些关键字的事件和/或具有指定字段的指定值的事件。 泳道可以绘制发生相关事件类型的事件(在一段时间内)。 特别地,每个这样的事件可以被分配给具有与事件时间匹配的桶时间的桶。 泳道可以沿着可视化中的时间线轴线延伸,并且桶可以被定位在沿轴线的表示铲斗时间的点上。 因此,可视化可以指示事件是否在某个时间点聚集。 因为可视化可以包括多个泳道,所以可视化可以进一步指示第一类型的事件的定时如何与第二类型的事件的定时比较。