Marko Jahnke · @markojahnke
66 followers · 227 posts · Server bonn.social

In the early 2000s, a student and myself developed an /#IDXP compliant security event message pipelining framework for collecting and consolidating messages from network , and products.

In the messages stream, we were able to match multi-stage in near real-time (in-memory), before everything was stored in central database. Structural graph-based was developed later by some colleagues.

We called it .

#cs #IDMEF #ids #EDR #correlation #DetectionRules #anomalydetection #MetaIDS

Last updated 4 years ago