发明名称 Detecting public network attacks using signatures and fast content analysis
摘要 Detecting attacks against computer systems by automatically detecting signatures based on predetermined characteristics of the intrusion. One aspect looks for commonalities among a number of different network messages, and establishes an intrusion signature based on those commonalities. Data reduction techniques, such as a hash function, are used to minimize the amount of resources which are necessary to establish the commonalities. In an embodiment, signatures are created based on the data reduction hash technique. Frequent signatures are found by reducing the signatures using that hash technique. Each of the frequent signatures is analyzed for content, and content which is spreading is flagged as being a possible attack. Additional checks can also be carried out to look for code within the signal, to look for spam, backdoors, or program code.
申请公布号 US7966658(B2) 申请公布日期 2011.06.21
申请号 US20040822226 申请日期 2004.04.08
申请人 THE REGENTS OF THE UNIVERSITY OF CALIFORNIA 发明人 SINGH SUMEET;VARGHESE GEORGE;ESTAN CRISTI;SAVAGE STEFAN
分类号 G08B23/00;G06F11/30;G06F12/14;G06F21/00;H04L9/00;H04L9/32;H04L29/06 主分类号 G08B23/00
代理机构 代理人
主权项
地址