发明名称 Flow-based detection of network intrusions
摘要 A flow-based intrusion detection system for detecting intrusions in computer communication networks. Data packets representing communications between hosts in a computer-to-computer communication network are processed and assigned to various client/server flows. Statistics are collected for each flow. Then, the flow statistics are analyzed to determine if the flow appears to be legitimate traffic or possible suspicious activity. A concern index value is assigned to each flow that appears suspicious. By assigning a value to each flow that appears suspicious and adding that value to the total concern index of the responsible host, it is possible to identify hosts that are engaged in intrusion activity. When the concern index value of a host exceeds a preset alarm value, an alert is issued and appropriate action can be taken.
申请公布号 US7185368(B2) 申请公布日期 2007.02.27
申请号 US20010000396 申请日期 2001.11.30
申请人 LANCOPE, INC. 发明人 COPELAND, III JOHN A.
分类号 G06F11/30;G06F21/00;H04L29/06 主分类号 G06F11/30
代理机构 代理人
主权项
地址