发明名称 Intrusion detection system using self-organizing clusters
摘要 An intrusion detection system (IDS). An IDS which has been configured in accordance with the present invention can include a traffic sniffer for extracting network packets from passing network traffic; a traffic parser configured to extract individual data from defined packet fields of the network packets; and, a traffic logger configured to store individual packet fields of the network packets in a database. A vector builder can be configured to generate multi-dimensional vectors from selected features of the stored packet fields. Notably, at least one self-organizing clustering module can be configured to process the multi-dimensional vectors to produce a self-organized map of clusters. Subsequently, an anomaly detector can detect anomalous correlations between individual ones of the clusters in the self-organized map based upon at least one configurable correlation metric. Finally, a classifier can classify detected anomalous correlations as one of an alarm and normal behavior.
申请公布号 US7017186(B2) 申请公布日期 2006.03.21
申请号 US20020208485 申请日期 2002.07.30
申请人 STEELCLOUD, INC. 发明人 DAY CHRISTOPHER W.
分类号 G06F11/00;G06F15/173;H04L29/06 主分类号 G06F11/00
代理机构 代理人
主权项
地址