|
Information Correlation
Activeworx® correlation engine adds real
time correlation to the Activeworx Event Framework. It does
this by using simple flow chart symbols to create complex rules
that have the ability to correlate against existing data and
incoming events. When a suspect event is detected, Activeworx
takes action based on those rules to check other security information
in the system making sure that the event is a real threat. It
also has the ability to group events with commonalities, such
as those involved in Brute Force attacks, into a single event
with more in-depth information.

(Click for larger image)
|