发明名称 PACKET SAMPLING FLOW-BASED DETECTION OF NETWORK INTRUSIONS
摘要 A flow-based intrusion detection sy stem ( 150) for detecting intrusions in computer communication networks ( 199) Data packets (101 ) representing communications between hosts in a computer-to-computer communication network (199) are processed and assigned to various client/server flows (160, 162) Statistics are collected for each flow (160, 162) Then, the flow statistics are analyzed to determine if the flow appears to be legitimate traffic or possible suspicious activity A concern index value is assigned to each flow that appears suspicious (166) By assigning a value to each flow that appears suspicious and adding that value to the total concern index ( 162, 166)of the responsible host, it is possible to identify hosts that are engaged in intrusion activity When the concern index value (166) of a host exceeds a preset alarm value, an alert is issued and appropriate action can be taken.
申请公布号 WO2006127012(A3) 申请公布日期 2008.01.03
申请号 WO2005US18860 申请日期 2005.05.27
申请人 LANCOPE, INC.;COPELAND, JOHN, A.;JERRIM, JOHN 发明人 COPELAND, JOHN, A.;JERRIM, JOHN
分类号 G06F11/30;H04L9/00;H04L29/06 主分类号 G06F11/30
代理机构 代理人
主权项
地址