Extensible intrusion detection system

Electrical computers and digital processing systems: support – Multiple computer communication using cryptography – Protection at a particular protocol layer

Reexamination Certificate

Rate now

  [ 0.00 ] – not rated yet Voters 0   Comments 0

Details

C713S152000

Reexamination Certificate

active

07065657

ABSTRACT:
A system and method are disclosed for detecting intrusions in a host system on a network. The intrusion detection system comprises an analysis engine configured to use continuations and apply forward- and backward-chaining using rules. Also provided are sensors, which communicate with the analysis engine using a meta-protocol in which the data packet comprises a 4-tuple. A configuration discovery mechanism locates host system files and communicates the locations to the analysis engine. A file processing mechanism matches contents of a deleted file to a directory or filename, and a directory processing mechanism extracts deallocated directory entries from a directory, creating a partial ordering of the entries. A signature checking mechanism computes the signature of a file and compares it to previously computed signatures. A buffer overflow attack detector compares access times of commands and their associated files. The intrusion detection system further includes a mechanism for checking timestamps to identify and analyze forward and backward time steps in a log file.

REFERENCES:
patent: 5557742 (1996-09-01), Smaha et al.
patent: 5574898 (1996-11-01), Leblang et al.
patent: 5621889 (1997-04-01), Lermuzeaux et al.
patent: 5638509 (1997-06-01), Dunphy et al.
patent: 5649194 (1997-07-01), Miller et al.
patent: 5680585 (1997-10-01), Bruell
patent: 5724569 (1998-03-01), Andres
patent: 5757913 (1998-05-01), Bellare et al.
patent: 5778070 (1998-07-01), Mattison
patent: 5844986 (1998-12-01), Davis
patent: 5978791 (1999-11-01), Farber et al.
patent: 6134664 (2000-10-01), Walker
patent: 6269447 (2001-07-01), Maloney et al.
patent: 6321338 (2001-11-01), Porras et al.
patent: 6347374 (2002-02-01), Drake et al.
patent: 6484203 (2002-11-01), Porras et al.
patent: 6704874 (2004-03-01), Porras et al.
patent: 6708212 (2004-03-01), Porras et al.
patent: 6711615 (2004-03-01), Porras et al.
patent: 2002/0083343 (2002-06-01), Crosbie et al.
patent: 2003/0204632 (2003-10-01), Willebeek-LeMair et al.
Undercoffer, J., et al, “Modeling Computer Attacks: A Target-Centric Ontology for Intrusion Detection”, Dept. of CS & EE, University of Maryland Baltimore County, 2002, “http://www.csee.umbc.edu/cadip/2002Symposium/Ont-for-IDS.pdf”, entire document.
Al-Shar, E., et al, “HiFi+: A Monitoring Virtual Machine for Autonomic Distributed Management”, School of CS, DePaul Univ., 2004, “http://www.mnlab.cs.depaul.edu/˜ehab/papers/dsom04.pdf, entire document”.
Mattsson, U., “A real time Intrusion Prevention System for Enterprise Databases”, Protegrity, Nov. 2004, “http://www.quest-pipelines.com
ewsletter-v5/1104_B.htm”, entire document.
Rebecca Bace, Introduction to Intrusion Detection Assesment, no date, for System and Network Security Management.
Gene H. Kim and Eugene H. Spafford, Writing, Supporting and Evaluating Tripwire: A Publically Available Security Tool, Mar. 12, 1994, Purdue Technical Report; Purdue University.
Douglas B. Moran et al., Derbi: Diagnosis, Explanation and Recovery From Break-Ins, no date, Artificial Intelligence Center SRI International.
Mabry Tyson, Ph.D., Explaining and Recovering From Computer Break-Ins, Jan. 12, 2001, SRI International.
Aleph One, Smashing the Stack for Fun and Profit, no date, vol. seven, Issue Forty-Nine; File 14 of 16 of BugTraq, r00t, and Underground.Org.
Donald C. Latham, Department of Defense Trusted Computer System Evaluation Criteria, Dec. 1985, Department of Defense Standard.
James P. Anderson Co., Computer Security Threat Monitoring and Surveillance, Feb. 26, 1980, Contract 79F296400.
Teresa F. Hunt et al., A Real-Time Intrusion-Detection Expert System (IDES), Feb. 28, 1992, SRI International Project 6784.

LandOfFree

Say what you really think

Search LandOfFree.com for the USA inventors and patents. Rate them and share your experience with other people.

Rating

Extensible intrusion detection system does not yet have a rating. At this time, there are no reviews or comments for this patent.

If you have personal experience with Extensible intrusion detection system, we encourage you to share that experience with our LandOfFree.com community. Your opinion is very important and Extensible intrusion detection system will most certainly appreciate the feedback.

Rate now

     

Profile ID: LFUS-PAI-O-3653679

  Search
All data on this website is collected from public sources. Our data reflects the most accurate information available at the time of publication.