发明名称 SYSTEM AND METHOD FOR USING SIGNATURES TO DETECT COMPUTER INTRUSIONS
摘要 <p>A system and method are disclosed for detecting intrusions in a host system on a network. The intrusion detection system comprises an analysis engine (302) configured to use continuation and apply forward- and backward-chaining using rules (306). Also provided are sensors (312), which communicate with the analysis engine using a metaprotocol in which the data packet comprises a 4-tuple. A configuration discovery mechanism locates host system files and communicates the locations to the analysis engine. A file processing mechanism matches contents of a deleted file to a directory or filename, and a directory processing mechanism extracts deallocated directory entries from a directory, creating a partial ordering of the entries. A signature checking mechanism computes the signature of a file and compares it to previously computed signatures (308). A buffer overflow attack detector compares access times of commands and their associated files. The intrusion detection system further includes a mechanism for checking timestamps to identify and analyze forward and backward time steps in a log file.</p>
申请公布号 WO2001017161(A1) 申请公布日期 2001.03.08
申请号 US2000023948 申请日期 2000.08.30
申请人 发明人
分类号 主分类号
代理机构 代理人
主权项
地址