发明名称 NETWORK PORT PROFILING
摘要 A port profiling system (155) detects unauthorized network usage (110). The port profiling system analyzes network communications (101, 199)to determine the service ports being used (181, 182, 183, 184, 185, 186). The system collects flow data (101, 162) from packet headers (162) between two hosts or Internet Protocol (IP) addresses. The collected flow data (160) is analyzed to determin e the associated network service provided (166). A host data structure (160, 166) is maintained containing a profile of the network services normally associated with the host (162). If the observed network service is not one of the normal network services performed as defined by th e port profile (160, 166) for that host, an alarm signal is generated (630) an d action (642) can be taken based upon the detection of an Out of Profile network service (610). An Out of Profile operation can indicate the operatio n of a Trojan Horse program (120) on the host, a scanning probe, or the existence of a non-approved network application that has been installed (160 , 162, 120).
申请公布号 CA2436710(A1) 申请公布日期 2002.08.08
申请号 CA20022436710 申请日期 2002.01.31
申请人 LANCOPE, INC. 发明人 COPELAND, JOHN A., III
分类号 G06F1/00;G06F11/30;G06F21/00;H04L29/06;(IPC1-7):G06F12/14 主分类号 G06F1/00
代理机构 代理人
主权项
地址