发明名称 Method and system for detecting intrusion into and misuse of a data processing system
摘要 Disclosed is a Security Indications and Warning (SI&W) Engine usable in conjunction with an audit agent. The audit agent forwards normalized audits to the SI&W Engine. The SI&W Engine groups the normalized audits into related groupings. Gauges are used to count the number of occurrences of audited events. A statistical engine provides statistical representations of the number of events per user, per session and per node. A predetermined number of criteria are defined a particular gauge or gauge pair. There may be many criteria for a particular network. When a predetermined number of criteria within a criteria set are triggered, an indicator is triggered. More complex indicators can use combinations of lower level indicators to provide further indications of potential security threads. Thus, a hierarchical system of gauges, criteria and indicators is used to measure boundary violations and breaches of different barriers. Advantageously, because there are no predefined scenarios or profiles that must be performed by a potential misuser or intruder, the SI&W Engine of the present invention is capable of indicating that a potential security threat exists in near-real time.
申请公布号 US6839850(B1) 申请公布日期 2005.01.04
申请号 US19990262027 申请日期 1999.03.04
申请人 PRC, INC. 发明人 CAMPBELL WAYNE A.;WALKER JEFFREY H.
分类号 G06F21/00;H04L29/06;(IPC1-7):G06F11/30;G06F15/173;G06F15/16 主分类号 G06F21/00
代理机构 代理人
主权项
地址