IP Library Granted Patent US 8,245,297
Granted Patent B2
US 8,245,297 · App. 10/488,657 · Granted Aug 14, 2012

Computer security event management system

Assignee: E-Cop Pte. Ltd.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,245,297
App. No.
10/488,657
Granted
Aug 14, 2012
Kind
B2
Abstract

A computer security event monitoring system comprising a trigger for generating a security event alert when a security event occurs and an event manager responsive to the generation of a security event alert. The alert is converted to an incident record by the event manager. The incident record is stored in a storage means and forwarded to an event reaction means for investigation of a reaction to the security event.

Claims (33)

1. A computer security event monitoring system comprising:

two or more input/output (I/O) modules for receiving alerts in different respective input stream protocols from one or more monitoring devices and for removing raw data from each alert; and

one or more technology specific (TS) modules for receiving the raw data via broadcasting from the I/O modules and for converting raw data relevant to the respective TS modules into incident records in a uniform format.

2. A computer security event monitoring system according to claim 1 , wherein the monitoring devices are provided for generation of the alerts, each monitoring device responsive to a different type of security event.

3. A computer security event monitoring system according to claim 2 , wherein one form of the monitoring devices is an intrusion detection system.

4. A computer security event monitoring system according to claim 2 , wherein one form of the monitoring devices is a firewall.

5. A computer security event monitoring system according to claim 1 , further comprising a reaction means for performing an assessment of the severity of the alerts and for prioritizing the incident records in a uniform format accordingly.

6. A computer security event monitoring system according to claim 5 , wherein the assessment is made by checking the alert against one or more rules for determining severity.

7. A computer security event monitoring system according to claim 5 , wherein the assessment is made by checking the alert against one or more rules for determining a reaction to respective security events that triggered the alerts.

8. A computer security event monitoring system according to claim 5 , wherein the reaction means is remotely located.

9. A computer security event monitoring system according to claim 1 , further comprising a standalone local security system coupled to a system to be monitored.

10. A computer security event monitoring system according to claim 1 , further comprising a distributed security system coupled to one or more systems to be monitored, wherein one or more components of the distributed security system are distributed remotely.

11. A computer security event monitoring system according to claim 1 , further comprising a distributed security system coupled to one or more systems to be monitored, wherein all components of the distributed security system are distributed remotely.

12. A computer security event monitoring system according to claim 1 , further comprising:

a master event manager for containing the I/O modules and at least one of the TS modules;

one or more slave event managers for containing at least one of the TS modules;

wherein the master event manager executes removal of raw data from each alert and distributes the raw data among the TS modules of the master event manager and the slave event managers via the broadcasting from the I/O modules.

13. A computer security event monitoring system according to claim 12 , wherein the TS modules convert raw data relevant to the respective TS modules into incident records in the uniform format and the incident records are forwarded to another site in a handoff process.

14. A computer security event monitoring system according to claim 12 , wherein the raw data distributed to the TS modules of the slave event managers are re-directed among the master event manager and the slave event managers.

15. A method of computer security event monitoring including the steps of:

providing two or more input/output (I/O) modules for receiving alerts in different respective input stream protocols from one or more monitoring devices and for removing raw data from each alert; and

providing one or more technology specific (TS) modules for receiving the raw data via broadcasting from the I/O modules and for converting raw data relevant to the respective TS modules into incident records in a uniform format.

16. A method of computer security event monitoring according to claim 15 , wherein the alerts are generated by a monitoring device in the form of an intrusion detection system.

17. A method of computer security event monitoring according to claim 15 , wherein the alerts are generated by a monitoring device in the form of a firewall software application.

18. A method of computer security event monitoring according to claim 15 , wherein the alerts are generated in a plurality of formats.

19. A method of computer security event monitoring according to claim 15 , further comprising providing a reaction means for performing an assessment of the severity of the alerts and for prioritizing the incident records in a uniform format accordingly.

20. A method of computer security event monitoring according to claim 15 , wherein the assessment is conducted by checking the alerts against one or more rules for determining a reaction to the alerts.

21. A method of computer security event monitoring according to claim 15 , further comprising:

providing a master event manager for containing the I/O modules and at least one of the TS modules;

providing one or more slave event managers for containing at least one of the TS modules;

wherein the master event manager executes removal of raw data from each alert and distributes the raw data among the TS modules of the master event manager and the slave event managers via the broadcasting from the I/O modules.

22. A method of computer security event monitoring according to claim 21 , wherein the TS modules convert raw data relevant to the respective TS modules into incident records in the uniform format and the incident records are forwarded to another site in a handoff process.

23. A method of computer security event monitoring according to claim 21 , wherein the raw data distributed to the TS modules of the slave event managers are re-directed among the master event manager and the slave event managers.

Assignments (7)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 25, 2019
From: ENSIGN INFOSECURITY (ASIA PACIFIC) PTE. LTD.
To: ENSIGN INFOSECURITY (CYBERSECURITY) PTE. LTD.
Reel/Frame 049582/0060 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 25, 2019
From: ENSIGN INFOSECURITY (CYBERSECURITY) PTE. LTD.
To: CERTIS CISCO SECURITY PTE LTD
Reel/Frame 049582/0294 →
CHANGE OF NAME Recorded Jun 25, 2019
From: QUANN SINGAPORE PTE. LTD.
To: ENSIGN INFOSECURITY (ASIA PACIFIC) PTE. LTD.
Reel/Frame 049587/0229 →
CHANGE OF NAME Recorded May 4, 2016
From: E-COP PTE. LTD.
To: QUANN SINGAPORE PTE. LTD.
Reel/Frame 038458/0934 →
CHANGE OF ADDRESS OF ASSIGNEE Recorded Sep 10, 2013
From: E-COP PTE. LTD.
To: E-COP PTE. LTD.
Reel/Frame 031200/0639 →
CHANGE OF NAME Recorded Feb 9, 2007
From: E-COP.NET PTE LTD.
To: E-COP PTE. LTD.
Reel/Frame 018924/0087 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 29, 2004
From: LIM, KENG LENG ALBERT
To: E-COP.NET PTE. LTD.
Reel/Frame 015718/0455 →
Continuity (1)
Related Publication 20040250133A1 · Dec 9, 2004