Inventors:
Rajeev Khanolkar - Edison NJ, US
Ozakil Azim - Cupertino CA, US
Rishi Asthana - Piscataway NJ, US
Niten Ved - Edison NJ, US
Kevin Hanrahan - Benicia CA, US
Amit Ghildiyal - Highland Park NJ, US
Shirisha Pogaku - South Plainfield NJ, US
Dhani Amaratunge - Somerset NJ, US
K. V. Rao Samavenkata - Edison NJ, US
Araf Karsh Hamid - Edison NJ, US
Assignee:
Netforensics, Inc. - Edison NJ
International Classification:
G06F 12/14, G06F 11/00
US Classification:
726 23, 709223, 709224, 726 1, 726 22
Abstract:
A computer system and method for detecting and monitoring network intrusion events from log data received from network service devices in a computer network, the computer system having discrete modules associated with a function performed on the log data received. An event parser in communication with at least one network service device is able to receive log data in real time from the device, and create an event object. An event manager in communication with the event parser is able to receive the event object and evaluate the event object according to at least one predetermined threshold condition such that, when the event object satisfies the predetermined threshold condition, the event manager designates the event object to be broadcast in real time. An event broadcaster in communication with the event manager receives event objects designated by the event manager for broadcast. The event broadcaster transmits the event object in real time as an intrusion alarm.