会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 5. 发明申请
    • Device, system and method for use of micro-policies in intrusion detection/prevention
    • 在入侵检测/预防中使用微观策略的设备,系统和方法
    • US20080196102A1
    • 2008-08-14
    • US11905980
    • 2007-10-05
    • Martin Frederick Roesch
    • Martin Frederick Roesch
    • G06F21/06
    • H04L63/1408G06F21/55G06F21/554
    • A method, computer system and/or computer readable medium, associates attack detection/prevention rules with a target in a communication network. The attack detection/prevention rules are provided for the target without differentiation as to flows. A particular flow is associated with a transmission destination, a port number, a platform, a network service, or a client application on the target. A micro-policy is bound to a target of the particular flow based on monitored transmissions. The micro-policy that was bound to the target of the particular flow, is applied to the target to detect an intrusion in the particular flow. Binding the micro-policy includes selecting, as the micro-policy, only rules in the attack detection/prevention rules that are specific to the port number, the protocol, the family of machine, and the version associated with the particular flow, and associating only the selected rules of the micro-policy with the target of the particular flow.
    • 方法,计算机系统和/或计算机可读介质将攻击检测/预防规则与通信网络中的目标相关联。 为目标提供攻击检测/预防规则,而不会流动。 特定流程与目标上的传输目的地,端口号,平台,网络服务或客户端应用相关联。 基于受监控的传输,微观策略必须与特定流的目标相关联。 绑定到特定流程的目标的微观政策被应用于目标以检测特定流程中的入侵。 绑定微观策略包括选择作为微策略的攻击检测/预防规则中仅特定于端口号,协议,机器族和与特定流相关联的版本的规则,以及关联 只有微观政策的选定规则与特定流程的目标。