首页> 外国专利> An apparatus and method for invasion detection system based on host system including access control function

An apparatus and method for invasion detection system based on host system including access control function

机译:基于包括访问控制功能的主机系统的入侵检测系统的装置和方法

摘要

PURPOSE: A host-based IDS(Intrusion Detection System) including an access control function on a kernel level and a method thereof are provided to offer a post and pre-intrusion detecting function by including an access controller for controlling execution of a system call on the kernel level. CONSTITUTION: A collector(303) collects/stores logs of a system call level generated by the system kernel(302). The access controller(301) judges intrusion by using the system call. An intrusion detector(304) judges the intrusion by comparing log information of the system call level generated from the system kernel with preset intrusion patterns. A countering part(305) executes confrontation for the detected intrusion according to preset countering methods and makes the log for a confronting result. A communicator(306) undertakes communication between an engine and a management console(307), sends the log received from the intrusion detector and the countering part to the management console, and transfers information for engine control from the management console to each part.
机译:用途:基于主机的IDS(入侵检测系统),包括在内核级别的访问控制功能及其方法,通过包括用于控制系统调用执行的访问控制器,提供入侵后和入侵前检测功能内核级别。构成:收集器(303)收集/存储由系统内核(302)生成的系统调用级别的日志。访问控制器(301)通过使用系统调用来判断入侵。入侵检测器(304)通过将从系统内核生成的系统调用级别的日志信息与预设的入侵模式进行比较来判断入侵。对抗部分(305)根据预设的对抗方法对检测到的入侵执行对抗,并记录对抗结果。通信器(306)在引擎和管理控制台(307)之间进行通信,将从入侵检测器和对接部分接收到的日志发送到管理控制台,并将用于引擎控制的信息从管理控制台传输到每个部分。

著录项

  • 公开/公告号KR100500586B1

    专利类型

  • 公开/公告日2005-07-12

    原文格式PDF

  • 申请/专利权人

    申请/专利号KR20030061543

  • 发明设计人 정준목;

    申请日2003-09-03

  • 分类号G06F15/00;

  • 国家 KR

  • 入库时间 2022-08-21 22:03:38

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号