发明授权
US07966658B2 Detecting public network attacks using signatures and fast content analysis
有权
使用签名和快速内容分析检测公共网络攻击
- 专利标题: Detecting public network attacks using signatures and fast content analysis
- 专利标题(中): 使用签名和快速内容分析检测公共网络攻击
-
申请号: US10822226申请日: 2004-04-08
-
公开(公告)号: US07966658B2公开(公告)日: 2011-06-21
- 发明人: Sumeet Singh , George Varghese , Cristi Estan , Stefan Savage
- 申请人: Sumeet Singh , George Varghese , Cristi Estan , Stefan Savage
- 申请人地址: US CA Oakland
- 专利权人: The Regents of the University of California
- 当前专利权人: The Regents of the University of California
- 当前专利权人地址: US CA Oakland
- 代理机构: Perkins Coie LLP
- 主分类号: G08B23/00
- IPC分类号: G08B23/00
摘要:
Detecting attacks against computer systems by automatically detecting signatures based on predetermined characteristics of the intrusion. One aspect looks for commonalities among a number of different network messages, and establishes an intrusion signature based on those commonalities. Data reduction techniques, such as a hash function, are used to minimize the amount of resources which are necessary to establish the commonalities. In an embodiment, signatures are created based on the data reduction hash technique. Frequent signatures are found by reducing the signatures using that hash technique. Each of the frequent signatures is analyzed for content, and content which is spreading is flagged as being a possible attack. Additional checks can also be carried out to look for code within the signal, to look for spam, backdoors, or program code.
公开/授权文献
信息查询