会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 2. 发明授权
    • Method and apparatus for storing intrusion rule
    • 存储入侵规则的方法和装置
    • US07735137B2
    • 2010-06-08
    • US11484257
    • 2006-07-10
    • Kwang Ho BaikByoung Koo KimJin Tae OhJong Soo JangSung Won Sohn
    • Kwang Ho BaikByoung Koo KimJin Tae OhJong Soo JangSung Won Sohn
    • G06F11/00G06F12/14G06F12/16G08B23/00
    • H04L63/1416
    • A method and apparatus for storing an intrusion rule are provided. The method stores a new intrusion rule in an intrusion detection system having already stored intrusion rules, and includes: generating combinations of divisions capable of dividing the new intrusion rule into a plurality of partial intrusion rules; calculating the frequency of hash value collisions between each of the generated division combinations and the already stored intrusion rules; dividing the new intrusion rule according to the division combination which has the lowest calculated frequency of hash value collisions; and storing the divided new intrusion rule in a corresponding position of the intrusion detection system. According to the method and apparatus, the size of the storage unit occupied by the intrusion rule can be reduced, and by performing pattern matching, the performance of the intrusion detection system can be enhanced.
    • 提供了一种用于存储入侵规则的方法和装置。 该方法在已经存储了入侵规则的入侵检测系统中存储新的入侵规则,并且包括:生成能够将新的入侵规则划分成多个部分入侵规则的分割组合; 计算每个生成的分割组合与已经存储的入侵规则之间的散列值冲突的频率; 根据哈希值碰撞计算频率最低的划分组合划分新的入侵规则; 并将分割的新入侵规则存储在入侵检测系统的相应位置。 根据该方法和装置,可以减少入侵规则占用的存储单元的大小,通过执行模式匹配,能够提高入侵检测系统的性能。
    • 3. 发明授权
    • Method of storing pattern matching policy and method of controlling alert message
    • 存储模式匹配策略的方法和控制报警信息的方法
    • US07735128B2
    • 2010-06-08
    • US11635245
    • 2006-12-07
    • Byoung Koo KimKwang Ho BaikJin Tae OhJong Soo JangSung Won Sohn
    • Byoung Koo KimKwang Ho BaikJin Tae OhJong Soo JangSung Won Sohn
    • G06F9/00G06F7/04H04L9/00
    • H04L12/5602
    • A method of storing a pattern matching policy and a method of controlling an alert message are provided. The method includes (a) generating a content structure as a sub-structure of a header combination structure of a stored traffic pattern which is a policy to be newly applied to a pattern matching apparatus; (b) determining whether a content of the stored traffic pattern is identical to a content of an original traffic pattern stored in advance in the pattern matching apparatus; (c) allocating a content index of the content of the original traffic pattern to the content of the stored traffic pattern if the content of the stored traffic pattern is identical to the content of the original traffic pattern; and (d) determining whether a header combination structure of the original traffic pattern comprises only one content structure or more than one content structure and allocating a header index of the header combination structure of the stored traffic pattern to the header combination structure of the original traffic pattern if the header combination structure of the original traffic pattern is found to comprise only one content structure. Accordingly, it is possible to efficiently use hardware memories with limited storage capacities and effectively perform a pattern matching function.
    • 提供了一种存储模式匹配策略的方法和一种控制警报消息的方法。 该方法包括:(a)生成内容结构作为作为新应用于模式匹配装置的策略的存储的流量模式的头部组合结构的子结构; (b)确定存储的业务模式的内容是否与预先存储在模式匹配装置中的原始业务模式的内容相同; (c)如果存储的业务模式的内容与原始业务模式的内容相同,则将原始业务模式的内容的内容索引分配给所存储的业务模式的内容; 和(d)确定原始业务模式的报头组合结构是否仅包含一个内容结构或多于一个内容结构,并且将所存储的业务模式的报头组合结构的报头索引分配给原始业务的报头组合结构 如果发现原始流量模式的头组合结构仅包含一个内容结构,则模式。 因此,可以有效地使用具有有限存储容量的硬件存储器并且有效地执行模式匹配功能。
    • 8. 发明授权
    • Network intrusion detection and prevention system and method thereof
    • 网络入侵检测和预防系统及其方法
    • US07565693B2
    • 2009-07-21
    • US11023384
    • 2004-12-29
    • Seung Won ShinJintae OhKi Young KimJong Soo JangSung Won Sohn
    • Seung Won ShinJintae OhKi Young KimJong Soo JangSung Won Sohn
    • G06F11/00
    • H04L63/1416H04L63/12H04L69/22
    • The present invention relates to a network intrusion detection and prevention system. The system includes: a signature based detecting device; an anomaly behavior based detecting device; and a new signature creating and verifying device disposed between the signature based detecting device and the anomaly behavior based detecting device, wherein if the anomaly behavior based detecting device detects network-attack-suspicious packets, the new signature creating and verifying device collects and searches the detected suspicious packets for common information, and then creates a new signature on the basis of the searched common information and at the same time, verifies whether or not the created new signature is applicable to the signature based detecting device, and then registers the created new signature to the signature based detecting device if it is determined that the created new signature is applicable.
    • 本发明涉及网络入侵检测和预防系统。 该系统包括:基于签名的检测装置; 基于异常行为的检测装置; 以及设置在基于签名的检测装置和基于异常行为的检测装置之间的新的签名创建和验证装置,其中如果基于异常行为的检测装置检测到网络攻击可疑包,则新的签名创建和验证装置收集并搜索 检测出公用信息的可疑包,然后根据搜索到的公共信息创建新的签名,同时验证创建的新签名是否适用于基于签名的检测装置,然后注册创建的新的 如果确定所创建的新签名是可应用的,则签名到基于签名的检测设备。
    • 9. 发明授权
    • Current mode double-integration conversion apparatus
    • 电流模式双积分转换装置
    • US07990305B2
    • 2011-08-02
    • US12514066
    • 2007-11-13
    • Ji Man ParkYoung Soo ParkSung Ik JunJong Soo JangSung Won Sohn
    • Ji Man ParkYoung Soo ParkSung Ik JunJong Soo JangSung Won Sohn
    • H03M1/82
    • H03M1/52G04F10/105
    • A double-integration signal processing apparatus for pulse width amplification and A/D conversion is provided. The current mode double-integration conversion apparatus includes: a current mode double-integration unit which integrates an input current in a predetermined time interval and outputs an integration voltage; a comparison unit which compares the integration voltage output from the current mode double-integration unit with a predetermined comparison voltage V k and outputs an comparison pulse signal; and a gate logic unit which performs a logic operation by using the comparison pulse signal of the comparison unit and an internal signal and outputs an logic operation pulse signal. Accordingly, the current mode double-integration conversion apparatus can be applied to various sensors.
    • 提供了用于脉冲宽度放大和A / D转换的双积分信号处理装置。 电流模式双积分转换装置包括:电流模式双积分单元,其以预定时间间隔积分输入电流并输出积分电压; 比较单元,其将来自当前模式双积分单元的积分电压输出与预定比较电压V k进行比较,并输出比较脉冲信号; 以及门逻辑单元,其通过使用比较单元的比较脉冲信号和内部信号来执行逻辑运算,并输出逻辑运算脉冲信号。 因此,电流模式双重积分转换装置可以应用于各种传感器。