|
Alert correlation is a type of long analysis. It focuses on the process of clustering alerts (events), generated by NIDS and HIDS computer systems, to form higher-level pieces of information. Example of simple alert correlation is grouping invalid login attempts to report single incident like "10000 invalid login attempts on host X". == See also == * ACARM * ACARM-ng * OSSIM * Prelude Hybrid IDS * Snort 抄文引用元・出典: フリー百科事典『 ウィキペディア(Wikipedia)』 ■ウィキペディアで「Alert correlation」の詳細全文を読む スポンサード リンク
|