发明名称 Method and system for reducing the false alarm rate of network intrusion detection systems
摘要 According to one embodiment of the invention, a computerized method for reducing the false alarm rate of network intrusion detection systems includes receiving, from a network intrusion detection sensor, one or more data packets associated with an alarm indicative of a potential attack on a target host and identifying characteristics of the alarm from the data packets. The characteristics include at least an attack type and an operating system fingerprint of the target host. The method further includes identifying the operating system type from the operating system fingerprint, comparing the attack type to the operating system type, and indicating whether the target host is vulnerable to the attack based on the comparison.
申请公布号 US7805762(B2) 申请公布日期 2010.09.28
申请号 US20030685726 申请日期 2003.10.15
申请人 CISCO TECHNOLOGY, INC. 发明人 ROWLAND CRAIG H.
分类号 G06F15/16;G06F11/30;G08B;G08B23/00;H04L9/00;H04L29/06;H04L29/12 主分类号 G06F15/16
代理机构 代理人
主权项
地址