首页> 外国专利> Modular system for detecting, filtering and providing notice about attack events associated with network security

Modular system for detecting, filtering and providing notice about attack events associated with network security

机译:用于检测,过滤和提供与网络安全性相关的攻击事件的通知的模块化系统

摘要

A host-based intrusion detection system (HIDS) sensor that monitors system logs for evidence of malicious or suspicious application activity running in real time and monitors key system files for evidence of tampering. This system detects attacks targeted at the host system on which it is installed and monitors output to the system and audit logs. It is signature-based and identifies and analyzes system and audit messages for signs of system misuse or attack. The system monitors the logs of applications running on the host, including mail servers, web servers and FTP servers. The system also monitors system files and notifies the system administrator when key system and security files have been accessed, modified or even deleted.
机译:基于主机的入侵检测系统(HIDS)传感器,可监视系统日志以实时发现恶意或可疑应用程序活动的证据,并监视关键系统文件以防止篡改。该系统检测针对安装了该主机的主机系统的攻击,并监视对系统的输出和审核日志。它是基于签名的,可识别和分析系统和审核消息以发现系统滥用或攻击的迹象。系统监视主机上运行的应用程序的日志,包括邮件服务器,Web服务器和FTP服务器。当访问,修改或什至删除关键系统文件和安全文件时,系统还会监视系统文件并通知系统管理员。

著录项

  • 公开/公告号US2004049693A1

    专利类型

  • 公开/公告日2004-03-11

    原文格式PDF

  • 申请/专利权人 ENTERASYS NETWORKS INC.;

    申请/专利号US20020241145

  • 发明设计人 KEVIN DOUGLAS;

    申请日2002-09-11

  • 分类号G06F11/30;

  • 国家 US

  • 入库时间 2022-08-21 23:17:50

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号