发明名称 Event sequence detection
摘要 The invention relates to event sequence detection suitable for an intrusion detection system (IDS), for example. An event sequence including two or more stages in order, each of the stages including one or more events, is defined. Also defined is a filtering function for each of the stages, each filtering function providing a TRUE indication, when one of the events belonging to the respective event is received, and a FALSE indication otherwise. Still further at least one binding function for each of the stages is defined such that a pair of binding functions in two successive stages links the events in these two successive stages. Received event data is continuously evaluated with the filtering functions. When the evaluation results in a TRUE indication from one of the filter functions, at least one key value is derived from the received event data by the corresponding at least one binding function. Finally, it is determined that that the sequence has been detected, when a TRUE indication has been obtained in each stage in a timely order and the derived key values link the detected events in the successive stages . <IMAGE>
申请公布号 EP1418484(A2) 申请公布日期 2004.05.12
申请号 EP20030104056 申请日期 2003.11.03
申请人 STONESOFT CORPORATION 发明人 NURMELA, KARI
分类号 G06F1/00;G06F15/173;G06F21/00;H04L29/06;(IPC1-7):G06F1/00 主分类号 G06F1/00
代理机构 代理人
主权项
地址