发明名称 Computer network intrusion detection
摘要 <p>Detecting harmful or illegal intrusions into a computer network or into restricted portions of a computer network uses statistical analysis to match user commands and program names with a template sequence. Discrete correlation matching and permutation matching are used to match sequences. The result of the match is input to a feature builder and then a modeler to produce a score. The score indicates possible intrusion. A sequence of user commands and program names and a template sequence of known harmful commands and program names from a set of such templates are retrieved. A closeness factor indicative of the similarity between the user command sequence and a template sequence is derived from comparing the two sequences. The user command sequence is compared to each template sequence in the set of templates thereby creating multiple closeness or similarity measurements. These measurements are examined to determine which sequence template is most similar to the user command sequence. A frequency feature associated with the user command sequence and the most similar template sequence is calculated. It is determined whether the user command sequence is a potential intrusion into restricted portions of the computer network by examining output from a modeler using the frequency feature as one input. </p>
申请公布号 EP2278519(A3) 申请公布日期 2012.08.22
申请号 EP20100183489 申请日期 1999.12.07
申请人 VISA INTERNATIONAL SERVICE ASSOCIATION 发明人 DIEP, THANH, A.
分类号 G06F21/00 主分类号 G06F21/00
代理机构 代理人
主权项
地址