首页> 外国专利> FIREWALL SYSTEM AND METHOD VIA FEEDBACK FROM BROAD-SCOPE MONITORING FOR INTRUSION DETECTION

FIREWALL SYSTEM AND METHOD VIA FEEDBACK FROM BROAD-SCOPE MONITORING FOR INTRUSION DETECTION

机译:通过宽带监控进行入侵检测的防火墙系统和方法

摘要

A broad-scope intrusion detection system analyzes traffic coming into multiple hosts or other customers' computers or sites. This provides additional data for analysis as compared to systems that just analyze the traffic coming into one customer's site. Additional detection schemes can be used to recognize patterns that would otherwise be difficult or impossible to recognize with just a single customer detector. Standard signature detection methods can be used. Additionally, new signatures can be used based on broad-scope analysis goals. An anomaly is detected in the computer system, and then it is determined which devices or devices are anticipated to be affected by the anomaly in the future. These anticipated devices are then alerted to the potential for the future anomaly. The anomaly can be an intrusion or an intrusion attempt or reconnaissance activity.
机译:广域入侵检测系统分析进入多个主机或其他客户计算机或站点的流量。与仅分析进入一个客户站点的流量的系统相比,这为分析提供了更多数据。可以使用其他检测方案来识别否则仅用单个客户检测器将难以识别或无法识别的模式。可以使用标准的签名检测方法。此外,可以根据广泛的分析目标使用新的签名。在计算机系统中检测到异常,然后确定将来预期会影响到哪些设备。然后,将这些预期的设备发出警报,告知将来可能发生异常。异常可能是入侵或入侵尝试或侦察活动。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号