发明名称 Correlating network information and intrusion information to find the entry point of an attack upon a protected computer
摘要 A method for determining the entry point of an attack by a vandal such as a hacker upon a device such as a computer or a server such as a web server that operates under the protection of an intrusion detection system. Intrusion detection information regarding the attack and network information regarding the attack are correlated, and the entry point of the attack thereby deduced. In one embodiment, a source address of a message representative of the attack is found in a router table of a router that provides a connection supporting the attack. Logical ports of the connection are determined, and the corresponding physical ports found, thereby identifying the attack's entry point into the protected device.
申请公布号 US7845004(B2) 申请公布日期 2010.11.30
申请号 US20010917368 申请日期 2001.07.27
申请人 INTERNATIONAL BUSINESS MACHINES CORPORATION 发明人 BARDSLEY JEFFREY SCOTT;BROCK ASHLEY ANDERSON;KIM NATHANIEL WOOK;LINGAFELT CHARLES STEVEN
分类号 G08B23/00;G06F21/00;H04L29/06 主分类号 G08B23/00
代理机构 代理人
主权项
地址