发明名称 Cooperative intrusion detection ecosystem for IP reputation-based security
摘要 An intrusion detection system (IDS) is enhanced to operate in a cluster of such systems, and IDSs organized into a cluster cooperate to exchange IP reputation influencing events information between or among the cooperating systems in real-time to enhance overall system response time and to prevent otherwise hidden attacks from damaging network resources. An IDS includes an IP reputation analytics engine to analyze new and existing events, correlate information, and to raise potential alerts. The IP reputation analytics engines may implement an algorithm, such as a pattern matching algorithm, a continuous data mining algorithm, or the like, to facilitate this operation. Clustering IDS endpoints to share IP reputation influencing events, using the cluster-wide view to determine IP reputation, and feeding the cluster-wide view back to the IDS endpoints, provides for enhanced and early detection of threats that is much more reliable and scalable as compared to prior art techniques.
申请公布号 US2014059683(A1) 申请公布日期 2014.02.27
申请号 US201213591456 申请日期 2012.08.22
申请人 ASHLEY PAUL ANTHONY;INTERNATIONAL BUSINESS MACHINES CORPORATION 发明人 ASHLEY PAUL ANTHONY
分类号 G06F21/00 主分类号 G06F21/00
代理机构 代理人
主权项
地址