首页> 外国专利> METHOD AND SYSTEM FOR REDUCING THE FALSE ALARM RATE OF NETWORK INTRUSION DETECTION SYSTEMS

METHOD AND SYSTEM FOR REDUCING THE FALSE ALARM RATE OF NETWORK INTRUSION DETECTION SYSTEMS

机译:降低网络入侵检测系统虚假告警率的方法和系统

摘要

According to one embodiment of the invention, a method for reducing the falsealarm rate of network intrusion detection systems includes receiving an alarmindicating a network intrusion may have occurred, identifying characteristicsof the alarm, including at least an attack type and a target address, queryinga target host associated with the target address for an operating systemfingerprint, receiving the operating system fingerprint that includes theoperating system type from the target host, comparing the attack type to theoperating system type, and indicating whether the target host is vulnerable tothe attack based on the comparison.
机译:根据本发明的一个实施例,一种用于减少错误的方法。网络入侵检测系统的警报率包括接收警报指示可能已发生网络入侵,确定特征警报的类型,至少包括攻击类型和目标地址,与操作系统的目标地址关联的目标主机指纹,接收包含以下内容的操作系统指纹:目标主机的操作系统类型,将攻击类型与操作系统类型,并指示目标主机是否容易受到攻击基于比较的攻击。

著录项

  • 公开/公告号CA2479504C

    专利类型

  • 公开/公告日2010-07-13

    原文格式PDF

  • 申请/专利权人 CISCO TECHNOLOGY INC.;

    申请/专利号CA20032479504

  • 发明设计人 RHODES AARON L.;ROWLAND CRAIG H.;

    申请日2003-03-28

  • 分类号H04L12/26;H04L29/06;

  • 国家 CA

  • 入库时间 2022-08-21 18:42:44

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号