发明名称 Dynamic signature inspection-based network intrusion detection
摘要 A signature based dynamic network intrusion detection system (IDS) includes attack signature profiles which are descriptive of characteristics of known network security violations. The attack signature profiles are organized into sets of attack signature profiles according to security requirements of network objects on a network. Each network object is assigned a set of attack signature profiles which is stored in a signature profile memory together with association data indicative of which sets of attack signature profiles correspond to which network objects. A monitoring device monitors network traffic for data addressed to the network objects. Upon detecting a data packet addressed to one of the network objects, packet information is extracted from the data packet. The extracted information is utilized to obtain a set of attack signature profiles corresponding to the network object based on the association data. A virtual processor executes instructions associated with attack signature profiles to determine if the packet is associated with a known network security violation. An attack signature profile generator is utilized to generate additional attack signature profiles configured for processing by the virtual processor in the absence of any corresponding modification of the virtual processor.
申请公布号 US6279113(B1) 申请公布日期 2001.08.21
申请号 US19980090774 申请日期 1998.06.04
申请人 INTERNET TOOLS, INC. 发明人 VAIDYA VIMAL
分类号 H04L29/06;(IPC1-7):H04L9/00 主分类号 H04L29/06
代理机构 代理人
主权项
地址