首页> 外国专利> Method and system for detecting intrusion into and misuse of a data processing system

Method and system for detecting intrusion into and misuse of a data processing system

机译:用于检测对数据处理系统的入侵和滥用的方法和系统

摘要

A processing system intrusion and misuse detection system and method utilizes instructions for and steps of processing system inputs into events and processing the events with reference to a set of selectable misuses in a misuse engine to produce one or more misuse outputs. The system and method convert processing system generated inputs to events by establishing an event data structure that stores the event. The event data structure includes authentication information, subject information, and object information. Processing system audit trail records, system log file data, and system security state data are extracted from the processing system to form the event data structure. A signature data structure stores signatures that the misuse engine compares and matches to selectable misuses. The signature data structure includes an initial state for each selectable misuse, an end state for each selectable misuse, one or more sets of transition functions for each selectable misuse, and one or more states for each selectable misuse, which can include the end state or the initial state. Furthermore, a misuse output and an index are utilized so that for each selectable misuse element there is a mechanism for loading the signature data structure.
机译:处理系统入侵和滥用检测系统和方法利用以下指令和步骤:将系统输入处理为事件,并参考滥用引擎中的一组可选滥用来处理事件,以产生一个或多个滥用输出。该系统和方法通过建立存储事件的事件数据结构来将处理系统生成的输入转换为事件。事件数据结构包括认证信息,主题信息和对象信息。从处理系统中提取处理系统审核跟踪记录,系统日志文件数据和系统安全状态数据,以形成事件数据结构。签名数据结构存储误用引擎比较并匹配到可选误用的签名。签名数据结构包括每个可选滥用的初始状态,每个可选滥用的结束状态,每个可选滥用的一个或多个转换函数集,以及每个可选滥用的一个或多个状态,可以包括结束状态或终止状态。初始状态。此外,利用了滥用输出和索引,使得对于每个可选的滥用元素,存在一种用于加载签名数据结构的机制。

著录项

  • 公开/公告号US5557742A

    专利类型

  • 公开/公告日1996-09-17

    原文格式PDF

  • 申请/专利权人 HAYSTACK LABS INC.;

    申请/专利号US19940208019

  • 发明设计人 STEPHEN E. SMAHA;STEVEN R. SNAPP;

    申请日1994-03-07

  • 分类号G06F11/34;

  • 国家 US

  • 入库时间 2022-08-22 03:37:52

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号