发明名称 INTRUSION DETECTION SYSTEM
摘要 An intrusion detection system (IDS). An IDS which has been configured in accordance with the present invention can include a traffic sniffer for extracting network packets from passing network traffic; a traffic parser configured to extract individual data from defined packet fields of the network packets; and, a traffic logger configured to store individual packet fields of the network packets in a database. A vector builder can be configured to generate multi-dimensional vectors from selected features of the stored packet fields. Notably, at least one self-organizing clustering module can be configured to process the multi-dimensional vectors to produce a self-organized map of clusters. Subsequently, an anomaly detector can detect anomalous correlations between individual ones of the clusters in the self-organized map based upon at least one configurable correlation metric. Finally, a classifier can classify detected anomalous correlations as one of an alarm and normal behavior.
申请公布号 WO2004012063(A3) 申请公布日期 2004.04.08
申请号 WO2003US23877 申请日期 2003.07.30
申请人 ASGARD HOLDING, LLC 发明人 DAY, CHRISTOPHER, W.
分类号 H04L29/06 主分类号 H04L29/06
代理机构 代理人
主权项
地址
您可能感兴趣的专利