发明名称 Enabling network intrusion detection by representing network activity in graphical form utilizing distributed data sensors to detect and transmit activity data
摘要 A method, system, and computer program product for detecting and mapping activity occurring at and between devices on a computer network for utilization within an intrusion detection mechanism. An enhanced graph matching intrusion detection system (eGMIDS) utility executing on a control server provides data collection functions and data fusion techniques. The eGMIDS comprises multiple sensors and associated unique adaptors that are located at different remote devices of the network and utilized to detect specific types of activity occurring at the respective devices relevant to eGMIDS processing. The sensors convert the data into eGMIDS format and encapsulate the data in a special transmission packet that is transmitted to the control server. The eGMIDS utility converts the activity data within these packets into eGMIDS-usable format and then processes the converted data via a data fusion technique to generate a graphical representation of the network (devices) and the activity occurring at/amongst the various devices.
申请公布号 US8266697(B2) 申请公布日期 2012.09.11
申请号 US20060367944 申请日期 2006.03.04
申请人 COFFMAN THAYNE RICHARD;21ST CENTURY TECHNOLOGIES, INC. 发明人 COFFMAN THAYNE RICHARD
分类号 G06F11/00 主分类号 G06F11/00
代理机构 代理人
主权项
地址