发明授权
- 专利标题: Identifying applications for intrusion detection systems
- 专利标题(中): 识别入侵检测系统的应用程序
-
申请号: US11835923申请日: 2007-08-08
-
公开(公告)号: US08291495B1公开(公告)日: 2012-10-16
- 发明人: Bryan Burns , Siying Yang , Julien Sobrier
- 申请人: Bryan Burns , Siying Yang , Julien Sobrier
- 申请人地址: US CA Sunnyvale
- 专利权人: Juniper Networks, Inc.
- 当前专利权人: Juniper Networks, Inc.
- 当前专利权人地址: US CA Sunnyvale
- 代理机构: Shumaker & Sieffert, P.A.
- 主分类号: G06F11/00
- IPC分类号: G06F11/00
摘要:
An intrusion detection system (“IDS”) device is described that includes a flow analysis module to receive a first packet flow from a client and to receive a second packet flow from a server. The IDS includes a forwarding component to send the first packet flow to the server and the second packet flow to the client and a stateful inspection engine to apply one or more sets of patterns to the first packet flow to determine whether the first packet flow represents a network attack. The IDS also includes an application identification module to perform an initial identification of a type of software application and communication protocol associated with the first packet flow and to reevaluate the identification of the type of software application and protocol according to the second packet flow. The IDS may help eliminate false positive and false negative attack identifications.
信息查询