发明名称 Method for eliminating invalid intrusion alerts
摘要 The method for eliminating invalid intrusion alerts operates according to a set of filter rules that are generated from given firewall rules. As a filter that implements this method receives an intrusion alert, it directly matches the features of the alert against its own rules, and then decides the validity of the alert. By coupling with the method, various filter-rule sets could be generated for numerous firewalls that may be not on the same specification, and an on-line deployment method could be applied to deploy filter-rule sets for filters. By applying the invention, it is reachable to eliminate invalid intrusion alerts precisely and efficiently, and to deploy quickly and with less manpower.
申请公布号 US2007136813(A1) 申请公布日期 2007.06.14
申请号 US20050298021 申请日期 2005.12.08
申请人 WONG HSING-KUO 发明人 WONG HSING-KUO
分类号 G06F12/14 主分类号 G06F12/14
代理机构 代理人
主权项
地址
您可能感兴趣的专利