发明授权
US07904942B2 Method of updating intrusion detection rules through link data packet
有权
通过链路数据包更新入侵检测规则的方法
- 专利标题: Method of updating intrusion detection rules through link data packet
- 专利标题(中): 通过链路数据包更新入侵检测规则的方法
-
申请号: US12036163申请日: 2008-02-22
-
公开(公告)号: US07904942B2公开(公告)日: 2011-03-08
- 发明人: Meng Sun , Tom Chen , Win-Harn Liu
- 申请人: Meng Sun , Tom Chen , Win-Harn Liu
- 申请人地址: TW Taipei
- 专利权人: Inventec Corporation
- 当前专利权人: Inventec Corporation
- 当前专利权人地址: TW Taipei
- 代理机构: Apex Juris, pllc
- 代理商 Tracy M Heims
- 主分类号: G06F17/00
- IPC分类号: G06F17/00 ; G06F11/00 ; G06F12/14 ; G06F12/16 ; G08B23/00 ; H04L29/06
摘要:
A method of updating intrusion detection rules through a link data packet is used to dynamically update rules storages of Snort system hosts. Firstly, an update sponsor in the network transmits a link data packet with an intrusion detection rule to the Snort system host. The Snort system host acquires the intrusion detection rule from the received link data packet, and parses an operation type of the intrusion detection rule. Then, the Snort system host verifies the validity of the intrusion detection rule. Subsequently, the rules storage is updated according to the type of the valid intrusion detection rule and a rules tree.
公开/授权文献
信息查询