发明名称 Intrusion detection method and signature table
摘要 Performance of a pattern-matching intrusion detection system (IDS) is improved by ranking signatures in its signature table by likelihood of occurrence, so that the table may be searched efficiently. Occurrence data associated with signatures is kept, and the ranking adaptively revised according to updates of the data. When the IDS detects a system event, the signature table is searched. If the search does not find a signature matching the event, thereby suggesting that the event poses no threat, a null signature is added to the signature table in a strategic location to terminate future searches early. In one embodiment, null signatures may be stored in a cache. When a system event is detected, the cache is searched. If a match is not found, the signature table is searched. If a match is not found in the signature table, a null signature is cached.
申请公布号 US2003110393(A1) 申请公布日期 2003.06.12
申请号 US20010015377 申请日期 2001.12.12
申请人 INTERNATIONAL BUSINESS MACHINES CORPORATION 发明人 BROCK ASHLEY ANDERSON;KIM NATHANIEL WOOK;MCCLAIN KEVIN THOMAS
分类号 G06F21/00;H04L29/06;(IPC1-7):G06F11/30 主分类号 G06F21/00
代理机构 代理人
主权项
地址