ATE452360T1 - Verfahren und system zum analysieren und adressieren von alarmen aus netzwerkeindringdetektionssystemen - Google Patents

Verfahren und system zum analysieren und adressieren von alarmen aus netzwerkeindringdetektionssystemen

Info

Publication number
ATE452360T1
ATE452360T1 AT03753071T AT03753071T ATE452360T1 AT E452360 T1 ATE452360 T1 AT E452360T1 AT 03753071 T AT03753071 T AT 03753071T AT 03753071 T AT03753071 T AT 03753071T AT E452360 T1 ATE452360 T1 AT E452360T1
Authority
AT
Austria
Prior art keywords
analyzing
intrusion detection
detection systems
network intrusion
alarms
Prior art date
Application number
AT03753071T
Other languages
English (en)
Inventor
Craig Rowland
Nathan Cohen
Steven Shanklin
Steven Snapp
Stephen Campos
Steven A Burke
Original Assignee
Cisco Tech Inc
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Cisco Tech Inc filed Critical Cisco Tech Inc
Application granted granted Critical
Publication of ATE452360T1 publication Critical patent/ATE452360T1/de

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/14Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1408Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
    • H04L63/1416Event detection, e.g. attack signature detection
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/50Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
    • G06F21/55Detecting local intrusion or implementing counter-measures
    • G06F21/552Detecting local intrusion or implementing counter-measures involving long-term monitoring or reporting
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/14Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1408Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
    • H04L63/1425Traffic logging, e.g. anomaly detection
AT03753071T 2002-05-14 2003-05-14 Verfahren und system zum analysieren und adressieren von alarmen aus netzwerkeindringdetektionssystemen ATE452360T1 (de)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
US31924202P 2002-05-14 2002-05-14
PCT/US2003/015546 WO2003098413A1 (en) 2002-05-14 2003-05-14 Method and system for analyzing and addressing alarms from network intrusion detection systems

Publications (1)

Publication Number Publication Date
ATE452360T1 true ATE452360T1 (de) 2010-01-15

Family

ID=29549828

Family Applications (1)

Application Number Title Priority Date Filing Date
AT03753071T ATE452360T1 (de) 2002-05-14 2003-05-14 Verfahren und system zum analysieren und adressieren von alarmen aus netzwerkeindringdetektionssystemen

Country Status (7)

Country Link
EP (1) EP1504323B8 (de)
CN (1) CN100424609C (de)
AT (1) ATE452360T1 (de)
AU (1) AU2003243253B2 (de)
CA (1) CA2484461C (de)
DE (1) DE60330554D1 (de)
WO (1) WO2003098413A1 (de)

Families Citing this family (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
DE60334368D1 (de) 2002-03-29 2010-11-11 Cisco Tech Inc Verfahren und system zur verringerung der falschalarmrate von netzwerk-eindringdetektionssystemen
WO2012167066A2 (en) * 2011-06-01 2012-12-06 Wilmington Savings Fund Society, Fsb Method and system for providing information from third party applications to devices
US9106693B2 (en) * 2013-03-15 2015-08-11 Juniper Networks, Inc. Attack detection and prevention using global device fingerprinting
CN111371783B (zh) * 2020-03-02 2022-06-24 中国建设银行股份有限公司 一种sql注入攻击检测方法、装置、设备和存储介质
CN114650210B (zh) * 2020-12-21 2023-04-11 华为技术有限公司 告警处理方法及防护设备

Family Cites Families (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US6070244A (en) * 1997-11-10 2000-05-30 The Chase Manhattan Bank Computer network security management system
US6408391B1 (en) * 1998-05-06 2002-06-18 Prc Inc. Dynamic system defense for information warfare
US6275942B1 (en) * 1998-05-20 2001-08-14 Network Associates, Inc. System, method and computer program product for automatic response to computer system misuse using active response modules
US6564216B2 (en) * 1998-10-29 2003-05-13 Nortel Networks Limited Server manager
US6405318B1 (en) * 1999-03-12 2002-06-11 Psionic Software, Inc. Intrusion detection system
WO2000070464A1 (en) * 1999-05-14 2000-11-23 L-3 Communications Corporation Object oriented security analysis tool
US7574740B1 (en) * 2000-04-28 2009-08-11 International Business Machines Corporation Method and system for intrusion detection in a computer network
DE60334368D1 (de) * 2002-03-29 2010-11-11 Cisco Tech Inc Verfahren und system zur verringerung der falschalarmrate von netzwerk-eindringdetektionssystemen

Also Published As

Publication number Publication date
WO2003098413A8 (en) 2004-05-06
CN100424609C (zh) 2008-10-08
WO2003098413A1 (en) 2003-11-27
EP1504323B1 (de) 2009-12-16
EP1504323B8 (de) 2010-05-19
AU2003243253A1 (en) 2003-12-02
DE60330554D1 (de) 2010-01-28
CA2484461C (en) 2011-08-30
EP1504323A1 (de) 2005-02-09
AU2003243253B2 (en) 2009-12-03
CA2484461A1 (en) 2003-11-27
CN1653403A (zh) 2005-08-10

Similar Documents

Publication Publication Date Title
ATE483310T1 (de) Verfahren und system zur verringerung der falschalarmrate von netzwerk- eindringdetektionssystemen
WO2005041141A3 (en) Method and system for reducing the false alarm rate of network intrusion detection systems
DE602004024270D1 (de) Vorrichtung und Verfahren zur Kennzeichnungsgewinnung
WO2006052545A3 (en) Line monitoring system and method
WO2007022364A3 (en) Change audit method, apparatus and system
ATE354844T1 (de) System zur erkennung von eindringlingen in einem bevölkerten raum
ATE459184T1 (de) System und verfahren zur erkennung von eindringungen in ein computernetzwerk
WO2007009009A3 (en) Systems and methods for identifying sources of malware
DE59801977D1 (de) Verfahren zum überwachen eines vorgegebenen überwachungsbereiches
TW200612278A (en) Methods, computer program products and data structures for intrusion detection, interusion response and vulnerability remediation across target computer systems
DE60302379D1 (de) Radarverarbeitungssystem und Verfahren zur Erkennung und Überwachung von Zielen
WO2009037333A3 (en) Intrusion detection method and system
CN105894760A (zh) 具有报警监控和报告的基于云的大众市场报警系统
WO2003096152A3 (en) Method and apparatus for remotely monitoring a site
WO2007046844A3 (en) System and method for visual representation of a catastrophic event and coordination of response
WO2004055634A3 (en) Systems and methods for detecting a security breach in a computer system
ATE341024T1 (de) Verfahren, vorrichtung und computersoftware- produkt zur reaktion auf computereinbrüche
BR0317286A (pt) Sistema de gerenciamento de conteúdo
US7797116B2 (en) System and method of acoustic detection and location of fire sprinkler water discharge
DE50209644D1 (de) Aktuator-Sensor-Interface-System sowie Verfahren zum Betreiben eines solchen
CN113992435A (zh) 一种攻击检测溯源方法、装置及系统
CN108574839A (zh) 一种卡口设备异常检测方法及装置
DE60330554D1 (de) Verfahren und system zum analysieren und adressieren von alarmen aus netzwerkeindringdetektionssystemen
CN111212055A (zh) 非侵入式网站远程检测系统及检测方法
EP3851963A3 (de) Störfalldetektion und -verwaltung

Legal Events

Date Code Title Description
RER Ceased as to paragraph 5 lit. 3 law introducing patent treaties