- 专利标题: Systems and methods for automated intrusion detection
-
申请号: US16409735申请日: 2019-05-10
-
公开(公告)号: US11388188B2公开(公告)日: 2022-07-12
- 发明人: Rajpreet Singh Ahluwalia
- 申请人: The Boeing Company
- 申请人地址: US IL Chicago
- 专利权人: The Boeing Company
- 当前专利权人: The Boeing Company
- 当前专利权人地址: US IL Chicago
- 主分类号: H04L29/06
- IPC分类号: H04L29/06 ; H04L9/40 ; H04L61/5046
摘要:
Implementations provide automated intrusion alert-based blacklisting with minimal false positives that ignores regular business operations, scalable to accommodate the volume of IDS alerts received by high-traffic internet-accessible networked systems. Implementations identify and block hostile infrastructure IP addresses during the reconnaissance phase based on IDS alert(s). Each IDS alert is automatically reviewed in historical context and triggers IP blocking as necessary. Some implementations maintain TCP/IP handshake records, preventing blocking an IP used to conduct regular business operations on the network that a malicious party has spoofed to avoid identification. Based on the historical context of each IP address within the local network environment, specifically regular business operations traffic versus malicious traffic, the IP address is blocked only if the majority of connections therefrom are malicious. This approach provides substantial cost-savings; frees up resources and personnel otherwise necessary for manual processes; and increases overall network security through automated network defense.
信息查询