Login| Sign Up| Help| Contact|

Patent Searching and Data


Title:
METHOD AND DEVICE FOR INTRUSION DETECTION
Document Type and Number:
WIPO Patent Application WO/2010/017679
Kind Code:
A1
Abstract:
A method and device for intrusion detection are provided. The method includes allocating one detection unit or multiple detection units to each type of network attack event to be detected, and configuring the types of objects to be detected of the types of network attack events, the detection operators and the detection knowledge bases, at the time of intrusion detection, acquiring the network data packets in real time, and acquiring the objects to be detected included in the network data packets; then performing the intrusion detection by the corresponding detection unit according to the configured detection operators and the detection knowledge bases to generate a network attack alarm event. The intrusion detection device includes a data pretreatment unit, a data distribution unit, a detection grid including one detection unit or multiple detection units connected orderly and a configuration management unit connected with the units. The invention supports the precision detection of the various complicated network attack events, and the execution efficiency of the whole intrusion detection device is considered.

Inventors:
ZHOU LIDAN (CN)
LI BO (CN)
YE RUNGUO (CN)
ZHOU TAO (CN)
Application Number:
PCT/CN2008/072091
Publication Date:
February 18, 2010
Filing Date:
August 21, 2008
Export Citation:
Click for automatic bibliography generation   Help
Assignee:
VENUS INFO TECH INC (CN)
BEIJING VENUS INFORMATION SECU (CN)
ZHOU LIDAN (CN)
LI BO (CN)
YE RUNGUO (CN)
ZHOU TAO (CN)
International Classes:
H04L12/24
Foreign References:
CN1655526A2005-08-17
CN101201788A2008-06-18
US7356585B12008-04-08
Attorney, Agent or Firm:
AFD CHINA INTELLECTUAL PROPERTY LAW OFFICE (8 Xueqing Rd Haidian, Beijing 5, CN)
Download PDF: