首页> 外国专利> INTELLIGENT INTRUSION DETECTION UTILIZING CONTEXT-BASED GRAPH-MATCHING OF NETWORK ACTIVITY

INTELLIGENT INTRUSION DETECTION UTILIZING CONTEXT-BASED GRAPH-MATCHING OF NETWORK ACTIVITY

机译:利用基于上下文的网络活动图进行智能入侵检测

摘要

A method, system, and computer program product for utilizing a mapping of activity occurring at and between devices (132-138) on a computer network to detect and prevent network intrusions. An enhanced graph matching intrusion detection system (eGMIDS) 100 (including an eGMIDS utility 235) is provided that comprises data collection functions, data fusion techniques, graph matching algorithms, and secondary and other search mechanisms. Threats are modeled as a set of entities and interrelations between the entities and sample threat patterns are stored within a database. The eGMIDS utility 235 initiates a graph matching algorithm by which the threat patterns are compared within the generated activity graph via subgraph isomorphism. A multi-layered approach including a targeted secondary layer search following a match during a primary layer search is provided. Searches are tempered by attributes and constraints and the eGMIDS reduces the number of threat patterns searched by utilizing ontological generalization.
机译:一种用于利用在计算机网络上的设备(132-138)处和之间发生的活动的映射来检测和防止网络入侵的方法,系统和计算机程序产品。提供了增强的图匹配入侵检测系统(eGMIDS)100(包括eGMIDS实用程序235),其包括数据收集功能,数据融合技术,图匹配算法以及辅助搜索和其他搜索机制。威胁被建模为一组实体,并且实体与样本威胁模式之间的相互关系存储在数据库中。 eGMIDS实用程序235启动图匹配算法,通过该图匹配算法,通过子图同构在生成的活动图中比较威胁模式。提供了一种多层方法,其包括在主要层搜索期间的匹配之后的目标次要层搜索。搜索受到属性和约束的限制,eGMIDS减少了通过使用本体论泛化而搜索到的威胁模式的数量。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号