发明名称 Event detection/anomaly correlation heuristics
摘要 A system for detecting network intrusions and other conditions in a network is described. The system includes a plurality of collector devices that are disposed to collect data and statistical information on packets that are sent between nodes on a network. An aggregator device is disposed to receive data and statistical information from the plurality of collector devices. The aggregator device produces a connection table that maps each node on the network to a record that stores information about traffic to or from the node. The aggregator runs processes that determine network events from aggregating of anomalies into network events.
申请公布号 US2006173992(A1) 申请公布日期 2006.08.03
申请号 US20030701376 申请日期 2003.11.03
申请人 WEBER DANIEL;GOPALAN PREM;POLETTO MASSIMILIANO A 发明人 WEBER DANIEL;GOPALAN PREM;POLETTO MASSIMILIANO A.
分类号 G06F15/173 主分类号 G06F15/173
代理机构 代理人
主权项
地址