Intrusion filter for intrusion detection system

An embodiment of the present invention relates to an intrusion filter (100) for use in a detection defense system (DPS) and an intrusion detection defense system (IDPS), and to a method and apparatus for use in an intrusion detection defense system (IDPS). Embodiments of the invention also relate to...

Ausführliche Beschreibung

Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: JORUP, CARSTEN, JEPPESEN BEN
Format: Patent
Sprache:chi ; eng
Schlagworte:
Online-Zugang:Volltext bestellen
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
Beschreibung
Zusammenfassung:An embodiment of the present invention relates to an intrusion filter (100) for use in a detection defense system (DPS) and an intrusion detection defense system (IDPS), and to a method and apparatus for use in an intrusion detection defense system (IDPS). Embodiments of the invention also relate to a detection subsystem (300) and a collection and investigation system (400) comprising such an intrusion filter. The intrusion filter filters the exception indications such that exception indications identified as misreported exception indications are discarded. Otherwise, the anomaly indication is provided to a collection and survey system (400) for further processing. Thus, for example, the computational load on the system is reduced. In addition, embodiments of the invention also relate to corresponding methods and computer programs. 本发明的实施例涉及一种用于检测防御系统(detection prevention system,DPS)和入侵检测防御系统(intrusion detection prevention system,IDPS)的入侵过滤器(100)。本发明的实施例还涉及一种包括这种入侵过滤器的检测子系统(300)以及收集和调查系统(400)。所述入侵过滤器过滤异常指示,使得