发明名称 Computer intrusion detection system and method based on application monitoring
摘要 An intrusion detection system (IDS) that uses application monitors for detecting application-based attacks against computer systems. The IDS implements application monitors in the form of a software program to learn and monitor the behavior of system programs in order to detect attacks against computer hosts. The application monitors implement machine learning algorithms to provide a mechanism for learning from previously observed behavior in order to recognize future attacks that it has not seen before. The application monitors include temporal locality algorithms to increased the accuracy of the IDS. The IDS of the present invention may comprise a string-matching program, a neural network, or a time series prediction algorithm for learning normal application behavior and for detecting anomalies.
申请公布号 US7181768(B1) 申请公布日期 2007.02.20
申请号 US20000698159 申请日期 2000.10.30
申请人 CIGITAL 发明人 GHOSH ANUP K.;SCHATZ MICHAEL;MICHAEL CHRISTOPH C.;SCHWARTZBARD AARON
分类号 G06F19/00 主分类号 G06F19/00
代理机构 代理人
主权项
地址