发明名称 METHOD AND APPARATUS FOR AUTOMATED NETWORK-WIDE SURVEILLANCEAND SECURITY BREACH INTERVENTION
摘要 A network surveillance system includes a handler process (10) for capturing network packets and filtering invalid packets, a first and second continuous ly sorted record file (15a, 15b), and a scanner process (30) for scanning all sessions occurring on the network and checking for the presence of certain rules (38). When a rule is met, indicating a security incident, a variety of appropriate actions may be taken, including notifying a network security officer via electronic or other mail or recording or terminating a network session. The surveillance system operates completely independently of any other network traffic and the network file server and therefore has no impac t on network performance.
申请公布号 CA2274299(C) 申请公布日期 2002.06.11
申请号 CA19972274299 申请日期 1997.11.21
申请人 COMPUTER ASSOCIATES INTERNATIONAL, INC. 发明人 ESBENSEN, DANIEL
分类号 G06F13/00;G06F11/00;H04L12/26;H04L29/06;(IPC1-7):G06F11/00 主分类号 G06F13/00
代理机构 代理人
主权项
地址