Method and apparatus for detecting intrusions on a computer system

A method of detecting intrusions on a computer includes the step of identifying an internet protocol field range describing fields within internet protocol packets received by a computer. A connectivity range is also established which describes a distribution of network traffic received by the compu...

Ausführliche Beschreibung

Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: AMIDON KEITH E, GUPTA RAMESH M, VISSAMSETTI SRIKANT, JAIN PARVEEN K, HAEFFELE STEVE M, RAMAN ANANTH, GONG FENGMIN
Format: Patent
Sprache:eng
Schlagworte:
Online-Zugang:Volltext bestellen
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
container_end_page
container_issue
container_start_page
container_title
container_volume
creator AMIDON KEITH E
GUPTA RAMESH M
VISSAMSETTI SRIKANT
JAIN PARVEEN K
HAEFFELE STEVE M
RAMAN ANANTH
GONG FENGMIN
description A method of detecting intrusions on a computer includes the step of identifying an internet protocol field range describing fields within internet protocol packets received by a computer. A connectivity range is also established which describes a distribution of network traffic received by the computer. An internet protocol field threshold and a connectivity threshold are then determined from the internet protocol field range and connectivity range, respectively. During the operation of the computer, values are calculated for the internet protocol field range and connectivity range. These values are compared to the internet protocol metric threshold and connectivity metric threshold so as to identify an intrusion on the computer.
format Patent
fullrecord <record><control><sourceid>epo_EVB</sourceid><recordid>TN_cdi_epo_espacenet_US2003009699A1</recordid><sourceformat>XML</sourceformat><sourcesystem>PC</sourcesystem><sourcerecordid>US2003009699A1</sourcerecordid><originalsourceid>FETCH-epo_espacenet_US2003009699A13</originalsourceid><addsrcrecordid>eNrjZHDyTS3JyE9RSMwD4oKCxKLEktJihbT8IoWU1JLU5JLMvHSFzLySotLizPy8YoX8PIVEheT83ILSktQiheLK4pLUXB4G1rTEnOJUXijNzaDs5hri7KGbWpAfn1pckJicmpdaEh8abGRgYGxgYGlmaeloaEycKgAoMDNc</addsrcrecordid><sourcetype>Open Access Repository</sourcetype><iscdi>true</iscdi><recordtype>patent</recordtype></control><display><type>patent</type><title>Method and apparatus for detecting intrusions on a computer system</title><source>esp@cenet</source><creator>AMIDON KEITH E ; GUPTA RAMESH M ; VISSAMSETTI SRIKANT ; JAIN PARVEEN K ; HAEFFELE STEVE M ; RAMAN ANANTH ; GONG FENGMIN</creator><creatorcontrib>AMIDON KEITH E ; GUPTA RAMESH M ; VISSAMSETTI SRIKANT ; JAIN PARVEEN K ; HAEFFELE STEVE M ; RAMAN ANANTH ; GONG FENGMIN</creatorcontrib><description>A method of detecting intrusions on a computer includes the step of identifying an internet protocol field range describing fields within internet protocol packets received by a computer. A connectivity range is also established which describes a distribution of network traffic received by the computer. An internet protocol field threshold and a connectivity threshold are then determined from the internet protocol field range and connectivity range, respectively. During the operation of the computer, values are calculated for the internet protocol field range and connectivity range. These values are compared to the internet protocol metric threshold and connectivity metric threshold so as to identify an intrusion on the computer.</description><edition>7</edition><language>eng</language><subject>CALCULATING ; COMPUTING ; COUNTING ; ELECTRIC COMMUNICATION TECHNIQUE ; ELECTRIC DIGITAL DATA PROCESSING ; ELECTRICITY ; PHYSICS ; TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHICCOMMUNICATION</subject><creationdate>2003</creationdate><oa>free_for_read</oa><woscitedreferencessubscribed>false</woscitedreferencessubscribed></display><links><openurl>$$Topenurl_article</openurl><openurlfulltext>$$Topenurlfull_article</openurlfulltext><thumbnail>$$Tsyndetics_thumb_exl</thumbnail><linktohtml>$$Uhttps://worldwide.espacenet.com/publicationDetails/biblio?FT=D&amp;date=20030109&amp;DB=EPODOC&amp;CC=US&amp;NR=2003009699A1$$EHTML$$P50$$Gepo$$Hfree_for_read</linktohtml><link.rule.ids>230,308,776,881,25542,76289</link.rule.ids><linktorsrc>$$Uhttps://worldwide.espacenet.com/publicationDetails/biblio?FT=D&amp;date=20030109&amp;DB=EPODOC&amp;CC=US&amp;NR=2003009699A1$$EView_record_in_European_Patent_Office$$FView_record_in_$$GEuropean_Patent_Office$$Hfree_for_read</linktorsrc></links><search><creatorcontrib>AMIDON KEITH E</creatorcontrib><creatorcontrib>GUPTA RAMESH M</creatorcontrib><creatorcontrib>VISSAMSETTI SRIKANT</creatorcontrib><creatorcontrib>JAIN PARVEEN K</creatorcontrib><creatorcontrib>HAEFFELE STEVE M</creatorcontrib><creatorcontrib>RAMAN ANANTH</creatorcontrib><creatorcontrib>GONG FENGMIN</creatorcontrib><title>Method and apparatus for detecting intrusions on a computer system</title><description>A method of detecting intrusions on a computer includes the step of identifying an internet protocol field range describing fields within internet protocol packets received by a computer. A connectivity range is also established which describes a distribution of network traffic received by the computer. An internet protocol field threshold and a connectivity threshold are then determined from the internet protocol field range and connectivity range, respectively. During the operation of the computer, values are calculated for the internet protocol field range and connectivity range. These values are compared to the internet protocol metric threshold and connectivity metric threshold so as to identify an intrusion on the computer.</description><subject>CALCULATING</subject><subject>COMPUTING</subject><subject>COUNTING</subject><subject>ELECTRIC COMMUNICATION TECHNIQUE</subject><subject>ELECTRIC DIGITAL DATA PROCESSING</subject><subject>ELECTRICITY</subject><subject>PHYSICS</subject><subject>TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHICCOMMUNICATION</subject><fulltext>true</fulltext><rsrctype>patent</rsrctype><creationdate>2003</creationdate><recordtype>patent</recordtype><sourceid>EVB</sourceid><recordid>eNrjZHDyTS3JyE9RSMwD4oKCxKLEktJihbT8IoWU1JLU5JLMvHSFzLySotLizPy8YoX8PIVEheT83ILSktQiheLK4pLUXB4G1rTEnOJUXijNzaDs5hri7KGbWpAfn1pckJicmpdaEh8abGRgYGxgYGlmaeloaEycKgAoMDNc</recordid><startdate>20030109</startdate><enddate>20030109</enddate><creator>AMIDON KEITH E</creator><creator>GUPTA RAMESH M</creator><creator>VISSAMSETTI SRIKANT</creator><creator>JAIN PARVEEN K</creator><creator>HAEFFELE STEVE M</creator><creator>RAMAN ANANTH</creator><creator>GONG FENGMIN</creator><scope>EVB</scope></search><sort><creationdate>20030109</creationdate><title>Method and apparatus for detecting intrusions on a computer system</title><author>AMIDON KEITH E ; GUPTA RAMESH M ; VISSAMSETTI SRIKANT ; JAIN PARVEEN K ; HAEFFELE STEVE M ; RAMAN ANANTH ; GONG FENGMIN</author></sort><facets><frbrtype>5</frbrtype><frbrgroupid>cdi_FETCH-epo_espacenet_US2003009699A13</frbrgroupid><rsrctype>patents</rsrctype><prefilter>patents</prefilter><language>eng</language><creationdate>2003</creationdate><topic>CALCULATING</topic><topic>COMPUTING</topic><topic>COUNTING</topic><topic>ELECTRIC COMMUNICATION TECHNIQUE</topic><topic>ELECTRIC DIGITAL DATA PROCESSING</topic><topic>ELECTRICITY</topic><topic>PHYSICS</topic><topic>TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHICCOMMUNICATION</topic><toplevel>online_resources</toplevel><creatorcontrib>AMIDON KEITH E</creatorcontrib><creatorcontrib>GUPTA RAMESH M</creatorcontrib><creatorcontrib>VISSAMSETTI SRIKANT</creatorcontrib><creatorcontrib>JAIN PARVEEN K</creatorcontrib><creatorcontrib>HAEFFELE STEVE M</creatorcontrib><creatorcontrib>RAMAN ANANTH</creatorcontrib><creatorcontrib>GONG FENGMIN</creatorcontrib><collection>esp@cenet</collection></facets><delivery><delcategory>Remote Search Resource</delcategory><fulltext>fulltext_linktorsrc</fulltext></delivery><addata><au>AMIDON KEITH E</au><au>GUPTA RAMESH M</au><au>VISSAMSETTI SRIKANT</au><au>JAIN PARVEEN K</au><au>HAEFFELE STEVE M</au><au>RAMAN ANANTH</au><au>GONG FENGMIN</au><format>patent</format><genre>patent</genre><ristype>GEN</ristype><title>Method and apparatus for detecting intrusions on a computer system</title><date>2003-01-09</date><risdate>2003</risdate><abstract>A method of detecting intrusions on a computer includes the step of identifying an internet protocol field range describing fields within internet protocol packets received by a computer. A connectivity range is also established which describes a distribution of network traffic received by the computer. An internet protocol field threshold and a connectivity threshold are then determined from the internet protocol field range and connectivity range, respectively. During the operation of the computer, values are calculated for the internet protocol field range and connectivity range. These values are compared to the internet protocol metric threshold and connectivity metric threshold so as to identify an intrusion on the computer.</abstract><edition>7</edition><oa>free_for_read</oa></addata></record>
fulltext fulltext_linktorsrc
identifier
ispartof
issn
language eng
recordid cdi_epo_espacenet_US2003009699A1
source esp@cenet
subjects CALCULATING
COMPUTING
COUNTING
ELECTRIC COMMUNICATION TECHNIQUE
ELECTRIC DIGITAL DATA PROCESSING
ELECTRICITY
PHYSICS
TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHICCOMMUNICATION
title Method and apparatus for detecting intrusions on a computer system
url https://sfx.bib-bvb.de/sfx_tum?ctx_ver=Z39.88-2004&ctx_enc=info:ofi/enc:UTF-8&ctx_tim=2025-02-06T02%3A42%3A19IST&url_ver=Z39.88-2004&url_ctx_fmt=infofi/fmt:kev:mtx:ctx&rfr_id=info:sid/primo.exlibrisgroup.com:primo3-Article-epo_EVB&rft_val_fmt=info:ofi/fmt:kev:mtx:patent&rft.genre=patent&rft.au=AMIDON%20KEITH%20E&rft.date=2003-01-09&rft_id=info:doi/&rft_dat=%3Cepo_EVB%3EUS2003009699A1%3C/epo_EVB%3E%3Curl%3E%3C/url%3E&disable_directlink=true&sfx.directlink=off&sfx.report_link=0&rft_id=info:oai/&rft_id=info:pmid/&rfr_iscdi=true