发明名称 Firewall system and method via feedback from broad-scope monitoring for intrusion detection
摘要 A broad-scope intrusion detection system analyzes traffic coming into multiple hosts or other customers' computers or sites. This provides additional data for analysis as compared to systems that just analyze the traffic coming into one customer's site. Additional detection schemes can be used to recognize patterns that would otherwise be difficult or impossible to recognize with just a single customer detector. Standard signature detection methods can be used. Additionally, new signatures can be used based on broad-scope analysis goals. An anomaly is detected in the computer system, and then it is determined which devices or devices are anticipated to be affected by the anomaly in the future. These anticipated devices are then alerted to the potential for the future anomaly. The anomaly can be an intrusion or an intrusion attempt or reconnaissance activity.
申请公布号 US2003188191(A1) 申请公布日期 2003.10.02
申请号 US20020108078 申请日期 2002.03.26
申请人 AARON JEFFREY A.;ANSCHUTZ THOMAS 发明人 AARON JEFFREY A.;ANSCHUTZ THOMAS
分类号 H04L29/06;(IPC1-7):H04L9/00 主分类号 H04L29/06
代理机构 代理人
主权项
地址