发明申请
- 专利标题: Method and Device for Intrusion Detection
- 专利标题(中): 入侵检测方法和设备
-
申请号: US12920462申请日: 2008-08-21
-
公开(公告)号: US20110016528A1公开(公告)日: 2011-01-20
- 发明人: Lidan Zhou , Bo Li , Runguo Ye , Tao Zhou
- 申请人: Lidan Zhou , Bo Li , Runguo Ye , Tao Zhou
- 申请人地址: CN Beijing CN Beijing
- 专利权人: Venus Info Tech Inc.,Beijing Venus Information Security Technology Comp any Limited
- 当前专利权人: Venus Info Tech Inc.,Beijing Venus Information Security Technology Comp any Limited
- 当前专利权人地址: CN Beijing CN Beijing
- 优先权: CN200810117941.8 20080815
- 国际申请: PCT/CN2008/072091 WO 20080821
- 主分类号: G06F11/00
- IPC分类号: G06F11/00
摘要:
A method and device for intrusion detection are provided. The method comprises: allocating one or more detection units for each type of network attack event to detect and configuring the type of object to detect of this type of network attack event, a detection operator and a detection knowledge base; in intrusion detection, acquiring network data packets in real time and acquiring the objects to detect included therein; then corresponding detection units performing intrusion detection according to the detection operators and detection knowledge bases configured, so as to generate network attack alarm events. The intrusion detection device comprises sequentially connected data pre-processing unit, data distribution unit and detection grid including one or more detection units, and a configuration management unit connected with them. The present invention supports accurate detection of various complex network attack events and considers the execution efficiency of the entire intrusion detection device.
信息查询