Method for configuring a network intrusion detection system
    1.
    发明授权
    Method for configuring a network intrusion detection system 失效
    配置网络入侵检测系统的方法

    公开(公告)号:US07228564B2

    公开(公告)日:2007-06-05

    申请号:US10627374

    申请日:2003-07-24

    IPC分类号: G06F11/00

    CPC分类号: H04L63/1408

    摘要: Disclosed is a method for configuring an intrusion detection system in a network which comprises determining a location in the network for a deployed intrusion detection sensor of the intrusion detection system, deploying the intrusion detection sensor in the determined location, enabling the intrusion detection sensor to monitor communication in a portion of the network, tuning the intrusion detection sensor to an appropriate level of awareness of the content in the communication in the network, prioritizing responses generated by the intrusion detection sensor to achieve an appropriate response to a detected intrusion in the network, configuring intrusion response mechanisms in the network to achieve an appropriate response by the mechanisms; and re-tuning the intrusion detection sensor in response to a prior intrusion detection.

    摘要翻译: 公开了一种在网络中配置入侵检测系统的方法,包括:确定入侵检测系统的部署入侵检测传感器在网络中的位置,将入侵检测传感器部署在确定的位置,使入侵检测传感器能够监视 在网络的一部分中进行通信,将入侵检测传感器调整到对网络中的通信中的内容的适当级别的感知,优先考虑由入侵检测传感器生成的响应以实现对网络中检测到的入侵的适当响应, 配置网络中的入侵响应机制,实现机制的适当响应; 并且响应于先前的入侵检测重新调整入侵检测传感器。

    Method for configuring a network intrusion detection system
    2.
    发明申请
    Method for configuring a network intrusion detection system 失效
    配置网络入侵检测系统的方法

    公开(公告)号:US20050039047A1

    公开(公告)日:2005-02-17

    申请号:US10627374

    申请日:2003-07-24

    IPC分类号: H04L9/00 H04L29/06

    CPC分类号: H04L63/1408

    摘要: Disclosed is a method for configuring an intrusion detection system in a network which comprises determining a location in the network for a deployed intrusion detection sensor of the intrusion detection system, deploying the intrusion detection sensor in the determined location, enabling the intrusion detection sensor to monitor communication in a portion of the network, tuning the intrusion detection sensor to an appropriate level of awareness of the content in the communication in the network, prioritizing responses generated by the intrusion detection sensor to achieve an appropriate response to a detected intrusion in the network, configuring intrusion response mechanisms in the network to achieve an appropriate response by the mechanisms; and re-tuning the intrusion detection sensor in response to a prior intrusion detection.

    摘要翻译: 公开了一种在网络中配置入侵检测系统的方法,包括:确定入侵检测系统的部署入侵检测传感器在网络中的位置,将入侵检测传感器部署在确定的位置,使入侵检测传感器能够监视 在网络的一部分中进行通信,将入侵检测传感器调整到对网络中的通信中的内容的适当级别的感知,优先考虑由入侵检测传感器生成的响应以实现对网络中检测到的入侵的适当响应, 配置网络中的入侵响应机制,实现机制的适当响应; 并且响应于先前的入侵检测重新调整入侵检测传感器。

    Configuring templates for an application and network management system
    3.
    发明申请
    Configuring templates for an application and network management system 有权
    为应用程序和网络管理系统配置模板

    公开(公告)号:US20050027835A1

    公开(公告)日:2005-02-03

    申请号:US10632446

    申请日:2003-07-31

    摘要: Methods and Systems for configuring secure templates for an application and network management system to provide network security. A template for an application and network management system is configured with first information for determining whether at least one message received by the template should or should not be processed by the template. The template is configured with second information for processing data associated with at least one received message. The template is configured with third information for preventing the communication of at least one received message to other templates for the application and network management system.

    摘要翻译: 为应用程序和网络管理系统配置安全模板以提供网络安全性的方法和系统。 用于应用和网络管理系统的模板配置有用于确定模板接收到的至少一个消息是否应该被模板处理的第一信息。 模板配置有用于处理与至少一个接收到的消息相关联的数据的第二信息。 该模板配置有用于防止至少一个接收的消息与用于应用和网络管理系统的其他模板的通信的第三信息。

    Method and system for testing provisioned services in a network
    4.
    发明申请
    Method and system for testing provisioned services in a network 有权
    网络中提供服务测试的方法和系统

    公开(公告)号:US20070171834A1

    公开(公告)日:2007-07-26

    申请号:US11338203

    申请日:2006-01-24

    IPC分类号: H04L12/26

    CPC分类号: H04L41/50 H04L41/22 H04L43/50

    摘要: A method, system, and apparatus are provided for testing a service in a network. A simulated interface is created on a network device by a Network Management Station (NMS). Thereafter, an instruction is received at the simulated interface from the NMS. The instruction comprises a source address, a destination address and other information to test a service. The service is tested on the network device based on the received instruction. A response is generated from the test. The response indicates whether the service is Working as intended between the source address and the destination address. The response is sent from the simulated interface to the NMS.

    摘要翻译: 提供了一种用于测试网络中的服务的方法,系统和装置。 模拟接口由网络管理站(NMS)在网络设备上创建。 此后,在NMS的模拟接口处接收到指令。 该指令包括源地址,目的地地址和其他测试服务的信息。 该服务是根据接收到的指令在网络设备上进行测试的。 从测试中产生响应。 响应指示服务是否在源地址和目标地址之间按预期工作。 该响应从模拟接口发送到NMS。

    Configuring templates for an application and network management system
    5.
    发明授权
    Configuring templates for an application and network management system 有权
    为应用程序和网络管理系统配置模板

    公开(公告)号:US08065368B2

    公开(公告)日:2011-11-22

    申请号:US10632446

    申请日:2003-07-31

    IPC分类号: G06F15/16

    摘要: Methods and Systems for configuring secure templates for an application and network management system to provide network security. A template for an application and network management system is configured with first information for determining whether at least one message received by the template should or should not be processed by the template. The template is configured with second information for processing data associated with at least one received message. The template is configured with third information for preventing the communication of at least one received message to other templates for the application and network management system.

    摘要翻译: 为应用程序和网络管理系统配置安全模板以提供网络安全性的方法和系统。 用于应用和网络管理系统的模板配置有用于确定模板接收到的至少一个消息是否应该被模板处理的第一信息。 模板配置有用于处理与至少一个接收到的消息相关联的数据的第二信息。 该模板配置有用于防止至少一个接收的消息与用于应用和网络管理系统的其他模板的通信的第三信息。

    RPC port mapper integrity checker to improve security of a provisionable network
    6.
    发明授权
    RPC port mapper integrity checker to improve security of a provisionable network 有权
    RPC端口映射器完整性检查器,以提高可配置网络的安全性

    公开(公告)号:US07890999B2

    公开(公告)日:2011-02-15

    申请号:US10637172

    申请日:2003-08-07

    IPC分类号: G08B23/00

    CPC分类号: H04L63/123

    摘要: A method for verifying port integrity in a network, comprising: accessing port binding information in a port authorization file in the network, querying a port mapper in the network for a mapped port assignment, comparing the port assignment to the port binding, and initiating a response based on the results of the comparing.

    摘要翻译: 一种用于验证网络中的端口完整性的方法,包括:访问网络中的端口授权文件中的端口绑定信息,在网络中查询映射端口分配的端口映射器,将端口分配与端口绑定进行比较,以及启动端口绑定 基于比较结果的反应。

    Method and system for establishing a consistent password policy
    7.
    发明申请
    Method and system for establishing a consistent password policy 有权
    建立一致的密码策略的方法和系统

    公开(公告)号:US20050114673A1

    公开(公告)日:2005-05-26

    申请号:US10723119

    申请日:2003-11-25

    IPC分类号: G06F21/00 H04L29/06 H04K1/00

    摘要: Methods and systems for establishing a consistent password policy. A plurality of password policies is described in a computer usable password policy data structure. The computer usable password policy data structure is accessed by a password policy enforcement agent. Optionally, the computer usable password policy data structure is validated for authenticity by the password policy enforcement agent. Optionally, the password policy enforcement agent can report back to a centralized configuration and aggregation point repository in order to provide a consistent view of policy enforcement.

    摘要翻译: 建立一致的密码策略的方法和系统。 在计算机可用密码策略数据结构中描述了多个密码策略。 计算机可用密码策略数据结构由密码策略执行代理访问。 可选地,计算机可用密码策略数据结构由密码策略执行代理验证为真实性。 或者,密码策略执行代理可以报告回集中式配置和聚合点存储库,以提供一致的策略实施视图。

    Method and system for establishing a consistent password policy
    8.
    发明授权
    Method and system for establishing a consistent password policy 有权
    建立一致的密码策略的方法和系统

    公开(公告)号:US07849320B2

    公开(公告)日:2010-12-07

    申请号:US10723119

    申请日:2003-11-25

    IPC分类号: G06F21/00 H04L29/06

    摘要: Methods and systems for establishing a consistent password policy. A plurality of password policies is described in a computer usable password policy data structure. The computer usable password policy data structure is accessed by a password policy enforcement agent. Optionally, the computer usable password policy data structure is validated for authenticity by the password policy enforcement agent. Optionally, the password policy enforcement agent can report back to a centralized configuration and aggregation point repository in order to provide a consistent view of policy enforcement.

    摘要翻译: 建立一致的密码策略的方法和系统。 在计算机可用密码策略数据结构中描述了多个密码策略。 计算机可用密码策略数据结构由密码策略执行代理访问。 可选地,计算机可用密码策略数据结构由密码策略执行代理验证为真实性。 或者,密码策略执行代理可以报告回集中式配置和聚合点存储库,以提供一致的策略实施视图。

    Method and system for testing provisioned services in a network
    9.
    发明授权
    Method and system for testing provisioned services in a network 有权
    网络中提供服务测试的方法和系统

    公开(公告)号:US07680925B2

    公开(公告)日:2010-03-16

    申请号:US11338203

    申请日:2006-01-24

    IPC分类号: G06F15/173

    CPC分类号: H04L41/50 H04L41/22 H04L43/50

    摘要: A method, system, and apparatus are provided for testing a service in a network. A simulated interface is created on a network device by a Network Management Station (NMS). Thereafter, an instruction is received at the simulated interface from the NMS. The instruction comprises a source address, a destination address and other information to test a service. The service is tested on the network device based on the received instruction. A response is generated from the test. The response indicates whether the service is working as intended between the source address and the destination address. The response is sent from the simulated interface to the NMS.

    摘要翻译: 提供了一种用于测试网络中的服务的方法,系统和装置。 模拟接口由网络管理站(NMS)在网络设备上创建。 此后,在NMS的模拟接口处接收到指令。 指令包括源地址,目的地地址和其他测试服务的信息。 该服务是根据接收到的指令在网络设备上进行测试的。 从测试中产生响应。 该响应指示服务是否在源地址和目标地址之间按预期工作。 该响应从模拟接口发送到NMS。