发明名称 SYSTEM, METHOD AND COMPUTER PROGRAM PRODUCT FOR AUTOMATIC RESPONSE TO COMPUTER SYSTEM MISUSE USING ACTIVE RESPONSE MODULES
摘要 <p>A system, method and computer program product for automatic response to computer system misuse using active response modules (ARMs). ARMs are tools that allow static intrusion detection system applications the ability to dynamically increase security levels by allowing real-time responses to detected instances of computer misuse. Several classes, of ARMs exist which allow them to interface with several types of network elements found within a computing environment (e.g., firewalls, web servers, Kerberos servers, certificate authorities, etc.). The ARMs, once defined, are deployed in a 'plug and play' manner into an existing intrusion detection system within a computing environment. A user (e.g., system administrator) may then configure the ARMs by linking them to specific computer misuses. Upon receipt of an instance of the computer misuse from the intrusion detection system, each ARM linked to the misuse collects pertinent data from the intrusion detection system and invokes a response specified by the ARM class and the collected pertinent data.</p>
申请公布号 WO1999060462(A1) 申请公布日期 1999.11.25
申请号 US1998010394 申请日期 1998.05.21
申请人 发明人
分类号 主分类号
代理机构 代理人
主权项
地址