发明名称 Method and system for reducing the false alarm rate of network intrusion detection systems
摘要 According to one embodiment of the invention, a method for reducing the false alarm rate of network intrusion detection systems includes receiving an alarm indicating a network intrusion may have occurred, identifying characteristics of the alarm, including at least an attack type and a target address, querying a target host associated with the target address for an operating system fingerprint, receiving the operating system fingerprint that includes the operating system type from the target host, comparing the attack type to the operating system type, and indicating whether the target host is vulnerable to the attack based on the comparison.
申请公布号 US2003212910(A1) 申请公布日期 2003.11.13
申请号 US20030402649 申请日期 2003.03.28
申请人 ROWLAND CRAIG H.;RHODES AARON L. 发明人 ROWLAND CRAIG H.;RHODES AARON L.
分类号 G06F21/00;H04L12/26;H04L29/06;(IPC1-7):G06F11/30 主分类号 G06F21/00
代理机构 代理人
主权项
地址
您可能感兴趣的专利