发明名称 User, process, and application tracking in an intrusion detection system
摘要 Preferred embodiments combine audit records with other relevant information to identify and track the users, processes or applications responsible for an attack. Information that identifies a user, process, or application may be associated with subsequent audit records related to the user or process session; this information may also be associated with IDS alerts related to the session. By reliably identifying the source of user and process sessions, the preferred embodiments make it possible to selectively target the sessions and applications that are related to an intrusion or attack.
申请公布号 US2004024864(A1) 申请公布日期 2004.02.05
申请号 US20020209596 申请日期 2002.07.31
申请人 PORRAS PHILLIP ANDREW;FONG MARTIN WAYNE 发明人 PORRAS PHILLIP ANDREW;FONG MARTIN WAYNE
分类号 H04L29/06;(IPC1-7):G06F15/173 主分类号 H04L29/06
代理机构 代理人
主权项
地址