发明名称 TARGET-BASED SMB AND DCE/RPC PROCESSING FOR AN INTRUSION DETECTION SYSTEM OR INTRUSION PREVENTION SYSTEM
摘要 A method performed in a processor of an intrusion detection/prevention system (IDS/?PS) checks for valid packets in an SMB named pipe in a communication network. In a processor configured as an IDS/IPS, a packet in a transmission is received and a kind of application of a target of the packet is determined. Also, the data in the packet is inspected by the IDS/IPS as part of the SMB named pipe on only one of a condition that: (a) the FID in an SMB command header of the packet is valid (i) for segments/fragments in the SMB named pipe and (ii) for the determined kind of application of the target of the packet, as indicated by a reassembly table, and (b) the determined kind of application of the target of the packet does not check the FID, as indicated by the reassembly table.
申请公布号 WO2010045089(A1) 申请公布日期 2010.04.22
申请号 WO2009US59965 申请日期 2009.10.08
申请人 SOURCEFIRE, INC.;WEASE, KENNETH, TODD 发明人 WEASE, KENNETH, TODD
分类号 G06F11/00 主分类号 G06F11/00
代理机构 代理人
主权项
地址