发明名称 Limiting the output of alerts generated by an intrusion detection sensor during a denial of service attack
摘要 An intrusion detection system is improved by altering its signatures and thresholds during a denial of service attack, in order to decrease the rate at which an intrusion detection sensor sends alerts to an intrusion detection server. A governor within the sensor is associated with each signature. The governor may include an alert log, a timer, an alert-generation-rate threshold, and rules that prescribe actions to be taken when the alert-generation-rate threshold is exceeded. The governor records the generation time of each alert by the sensor, and determines the rate at which the sensor is presently generating alerts. When the present alert-generation rate exceeds the alert-generation-rate threshold, the governor alters the associated signature threshold to decrease the alert generation rate of the intrusion detection sensor.
申请公布号 US7308714(B2) 申请公布日期 2007.12.11
申请号 US20010966227 申请日期 2001.09.27
申请人 INTERNATIONAL BUSINESS MACHINES CORPORATION 发明人 BARDSLEY JEFFREY SCOTT;BROCK ASHLEY ANDERSON;KIM NATHANIEL WOOK;LINGAFELT CHARLES STEVEN
分类号 G06F21/00;G06F7/04;G06F11/00;G06F15/173;H04L29/06 主分类号 G06F21/00
代理机构 代理人
主权项
地址