会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 3. 发明授权
    • Phishing detection systems and methods
    • 网络钓鱼检测系统和方法
    • US09065850B1
    • 2015-06-23
    • US13022352
    • 2011-02-07
    • Julien Sobrier
    • Julien Sobrier
    • H04L29/06
    • H04L63/1483
    • The present disclosure provides phishing heuristic systems and methods that detect phishing sites. The present invention may be implemented via a server connected to the Internet, via a distributed security system, and the like. Phishing sites may be detected in a single transaction, i.e. client request plus server reply, while knowing as little as possible about the site being masqueraded. In an exemplary embodiment, a phishing site detection system and method utilized three steps—whitelisting, blacklisting, and scoring. For example, if a particular page meets all requirements of blacklisting without any elements of whitelisting and has a score over a particular threshold, that particular site may be designated as a phishing page.
    • 本公开提供了网络钓鱼启发式系统和检测网络钓鱼站点的方法。 本发明可以通过经由分布式安全系统等连接到因特网的服务器来实现。 在单个事务中可能会检测到网络钓鱼站点,即客户端请求加服务器回复,同时尽可能少地知道伪装的站点。 在示例性实施例中,网络钓鱼站点检测系统和方法使用三个步骤 - 白名单,黑名单和评分。 例如,如果特定页面满足黑名单的所有要求,而没有任何白名单元素并且具有超过特定阈值的分数,则该特定站点可被指定​​为网络钓鱼页面。
    • 4. 发明授权
    • Identifying applications for intrusion detection systems
    • 识别入侵检测系统的应用程序
    • US08291495B1
    • 2012-10-16
    • US11835923
    • 2007-08-08
    • Bryan BurnsSiying YangJulien Sobrier
    • Bryan BurnsSiying YangJulien Sobrier
    • G06F11/00
    • H04L63/0254H04L63/1441H04L63/168
    • An intrusion detection system (“IDS”) device is described that includes a flow analysis module to receive a first packet flow from a client and to receive a second packet flow from a server. The IDS includes a forwarding component to send the first packet flow to the server and the second packet flow to the client and a stateful inspection engine to apply one or more sets of patterns to the first packet flow to determine whether the first packet flow represents a network attack. The IDS also includes an application identification module to perform an initial identification of a type of software application and communication protocol associated with the first packet flow and to reevaluate the identification of the type of software application and protocol according to the second packet flow. The IDS may help eliminate false positive and false negative attack identifications.
    • 描述了入侵检测系统(IDS)设备,其包括用于从客户端接收第一分组流并从服务器接收第二分组流的流分析模块。 IDS包括将第一分组流发送到服务器的转发组件和到客户端的第二分组流以及状态检查引擎,以将一组或多组模式应用于第一分组流,以确定第一分组流是否代表 网络攻击 IDS还包括应用识别模块,用于执行与第一分组流相关联的软件应用和通信协议的类型的初始识别,并且根据第二分组流来重新评估软件应用和协议的类型的标识。 IDS可能有助于消除假阳性和假阴性攻击识别。