发明名称 Inline intrusion detection using a single physical port
摘要 In accordance with one embodiment of the present invention, a method for inline intrusion detection includes receiving a packet at a physical interface of an intrusion detection system. The packet is tagged with a first VLAN identifier associated with an external network. The network further includes buffering the packet at the physical interface, communicating a copy of the packet to a processor, and analyzing the copy of the packet at the processor to determine whether the packet includes an attack signature. The method also includes communicating a reply message from the processor to the interface indicating whether the packet includes an attack signature. If the packet does not contain an attack signature the buffered copy of the packet is re-tagged with a second VLAN identifier associated with a protected network and re-tagged packet is communicated to the protected network.
申请公布号 US7555774(B2) 申请公布日期 2009.06.30
申请号 US20040910194 申请日期 2004.08.02
申请人 CISCO TECHNOLOGY, INC. 发明人 HALL MICHAEL LEE;WILEY KEVIN L.;HOSSAIN MUNAWAR;SIRRIANNI JOSEPH M.
分类号 H04L29/00 主分类号 H04L29/00
代理机构 代理人
主权项
地址