Invention Grant
- Patent Title: Dynamic gathering of attack symptoms
-
Application No.: US16821375Application Date: 2020-03-17
-
Publication No.: US11425156B2Publication Date: 2022-08-23
- Inventor: Oded Sofer , Zamir Paltiel
- Applicant: INTERNATIONAL BUSINESS MACHINES CORPORATION
- Applicant Address: US NY Armonk
- Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
- Current Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
- Current Assignee Address: US NY Armonk
- Agent Dmitry Paskalov
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04L9/40 ; G06F16/24

Abstract:
Techniques for detecting network intrusions are disclosed. An example intrusion detection system includes a storage device to store audit data generated by a network traffic analyzer in accordance with an audit policy that determines an auditing level. The system also includes a processor to receive a case defined by a case definition, wherein the case definition comprises a plurality of symptoms and each symptom is defined by a separate symptom definition. The processor performs queries of the audit data in accordance with each of the symptoms to generate captured symptom data. The symptoms are scored based on the captured symptom data to generate symptom scores, and the symptom scores are summed to generate a case score. If the case score exceeds an alert threshold specified by the case definition, the processor issues an alert.
Public/Granted literature
- US20210297436A1 DYNAMIC GATHERING OF ATTACK SYMPTOMS Public/Granted day:2021-09-23
Information query