Fortinet, Inc.
Security information and event management

Last updated:

Abstract:

Systems and methods for conducting correlation analysis for security events with assets attributes of a network by a SIEM device to enable more efficient reporting are provided. According to one embodiment, when a SIEM device obtains a security event, a risk level of the security event is calculated based on at least a correlation of the security event with one or more asset attributes of a network that is managed by the SIEM device. When the risk level meets a predetermined or configurable threshold, the SIEM device causes the security event to be reported to an administrator of the network.

Status:
Grant
Type:

Utility

Filling date:

12 Oct 2013

Issue date:

7 Apr 2020