Invention Grant
- Patent Title: Event detection method and device
- Patent Title (中): 事件检测方法和设备
-
Application No.: US11753716Application Date: 2007-05-25
-
Publication No.: US07913304B2Publication Date: 2011-03-22
- Inventor: Bin Cao , Yong Wang
- Applicant: Bin Cao , Yong Wang
- Applicant Address: CN Shenyang
- Assignee: Neusoft Corporation
- Current Assignee: Neusoft Corporation
- Current Assignee Address: CN Shenyang
- Agency: Scully, Scott, Murphy & Presser, P.C.
- Priority: CN200610046168 20060324
- Main IPC: G06F12/14
- IPC: G06F12/14

Abstract:
The embodiments of the present invention disclose an event detection method and device. The method includes: predefining event-based detection rules with a predicative context-free grammar; generating by parsing the detection rules a parsing table of pushdown automaton which supports parallel parsing; receiving an event to be detected; and analyzing by a controller the event to be detected according to the parsing table, to obtain a detection result. The present invention is especially applicable to detection of network attack events. The embodiments of the present invention detect the attacks with a predicative context-free grammar on the basis of events, and ensure a close combination of a protocol parsing process and an attack detection process, as well as a close combination of multiple attack detection rules, thus decreasing unnecessary calculations. In addition, with an optimized parallel pushdown automaton, the embodiments of the present invention can efficiently analyze the predicative context-free grammar. Consequently, besides hierarchical processing capability and state description capability, the embodiments of the present invention deliver high efficiency.
Public/Granted literature
- US20080052780A1 EVENT DETECTION METHOD AND DEVICE Public/Granted day:2008-02-28
Information query