首页> 外国专利> Misuse intrusion detecting apparatus and method in misuse intrusion detecting system

Misuse intrusion detecting apparatus and method in misuse intrusion detecting system

机译:滥用入侵检测系统中的滥用入侵检测装置和方法

摘要

1. TECHNICAL FIELD OF THE INVENTION;The present invention relates to a misuse intrusion detection apparatus and method in the misuse intrusion detection system.;2. The technical problem to be solved by the invention;The present invention is a misuse intrusion detection apparatus and a method for realizing the method and the method to recognize and track which part of the intrusion scenario when the pattern currently being processed in the misuse intrusion detection system is a pattern belonging to the intrusion scenario. To provide a computer-readable recording medium that records the data.;3. Summary of the Solution of the Invention;The present invention includes intrusion determination means for determining whether an intrusion is made by receiving audit data or a packet from the outside and using a pattern progress recording file recorded in the pattern progress recording means; According to the pattern progress record file determined by the intrusion determination means, each pattern of the misuse intrusion scenario is composed of one record, and according to the order and the total number of patterns of each scenario, the current index value (current_index) and Misuse intrusion pattern storage means for storing a total index value (total_index); And the pattern progress recording means for managing a separate pattern progress recording file for each intrusion scenario to check whether the current pattern is a predetermined pattern of which intrusion scenario, and record the progress of each pattern.;4. Important uses of the invention;The present invention is used for misuse intrusion detection system and the like.
机译:滥用入侵检测设备和方法技术领域本发明涉及一种滥用入侵检测系统中的滥用入侵检测设备和方法。本发明要解决的技术问题;本发明是一种滥用入侵检测装置和方法,用于实现在滥用入侵检测中当前正在处理的模式时识别并跟踪入侵场景的哪一部分的方法和方法系统是属于入侵场景的一种模式。提供一种记录数据的计算机可读记录介质; 3。发明内容本发明包括:入侵确定装置,用于通过从外部接收审计数据或分组并使用记录在模式进度记录装置中的模式进度记录文件来确定是否进行了入侵;以及根据由入侵确定装置确定的模式进度记录文件,滥用入侵场景的每个模式由一个记录组成,并且根据每个场景的模式的顺序和总数,当前索引值(current_index)和滥用模式存储装置用于存储总索引值(total_index);以及模式进度记录装置,用于为每个入侵场景管理单独的模式进度记录文件,以检查当前模式是否是哪个入侵场景的预定模式,并记录每个模式的进度。本发明的重要用途;本发明用于滥用入侵检测系统等。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号