首页> 外国专利> METHOD AND SYSTEM FOR REDUCING THE FALSE ALARM RATE OF NETWORK INTRUSION DETECTION SYSTEMS

METHOD AND SYSTEM FOR REDUCING THE FALSE ALARM RATE OF NETWORK INTRUSION DETECTION SYSTEMS

机译:降低网络入侵检测系统虚假告警率的方法和系统

摘要

According to one embodiment of the invention, a method for reducing the false alarm rate of network intrusion detection systems includes receiving an alarm indicating a network intrusion may have occurred, identifying characteristics of the alarm, including at least an attack type and a target address, querying a target host associated with the target address for an operating system fingerprint, receiving the operating system fingerprint that includes the operating system type from the target host, comparing the attack type to the operating system type, and indicating whether the target host is vulnerable to the attack based on the comparison.
机译:根据本发明的一个实施例,一种用于减少网络入侵检测系统的错误警报率的方法包括:接收指示可能已经发生网络入侵的警报;识别警报的特征,至少包括攻击类型和目标地址;查询与目标地址相关联的目标主机的操作系统指纹,从目标主机接收包括操作系统类型的操作系统指纹,将攻击类型与操作系统类型进行比较,指示目标主机是否容易受到攻击基于比较的攻击。

著录项

  • 公开/公告号AU2003220582A1

    专利类型

  • 公开/公告日2003-10-13

    原文格式PDF

  • 申请/专利权人 CISCO TECHNOLOGY INC.;

    申请/专利号AU20030220582

  • 发明设计人 CRAIG H. ROWLAND;

    申请日2003-03-28

  • 分类号H04L29/06;H04L12/26;G06F1/00;

  • 国家 AU

  • 入库时间 2022-08-21 23:56:51

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号