发明申请
- 专利标题: Instrusion Detection Method and System, Related Network and Computer Program Product Therefor
- 专利标题(中): 入侵检测方法与系统,相关网络及其计算机程序产品
-
申请号: US11791609申请日: 2004-11-26
-
公开(公告)号: US20070300301A1公开(公告)日: 2007-12-27
- 发明人: Gianluca Cangini , Francesco Coda Zabetta , Gerardo Lamastra
- 申请人: Gianluca Cangini , Francesco Coda Zabetta , Gerardo Lamastra
- 国际申请: PCT/EP04/13424 WO 20041126
- 主分类号: G06F1/00
- IPC分类号: G06F1/00
摘要:
Intrusions in a system under surveillance are detected by matching the events occurring during operation of the system against a knowledge base including information on events which occurred during a learning phase. The detection technique includes the steps of: recording, during the learning phase, temporal data related to the events during the learning phase; identifying, as a function of the temporal data recorded, a dynamic part of the knowledge base; discovering patterns that cover the dynamic part of the knowledge base; and using, during the analysis phase, a regular expression match at least with respect to the dynamic part of the knowledge base.
公开/授权文献
信息查询