Invention Grant
- Patent Title: Method and system for reducing the false alarm rate of network intrusion detection systems
- Patent Title (中): 降低网络入侵检测系统误报率的方法和系统
-
Application No.: US10402649Application Date: 2003-03-28
-
Publication No.: US07886357B2Publication Date: 2011-02-08
- Inventor: Craig H. Rowland , Aaron L. Rhodes
- Applicant: Craig H. Rowland , Aaron L. Rhodes
- Applicant Address: US CA San Jose
- Assignee: Cisco Technology, Inc.
- Current Assignee: Cisco Technology, Inc.
- Current Assignee Address: US CA San Jose
- Agency: Baker Botts L.L.P.
- Main IPC: G06F11/00
- IPC: G06F11/00 ; G06F12/14 ; G06F12/16 ; G06F15/18 ; G08B23/00

Abstract:
According to one embodiment of the invention, a method for reducing the false alarm rate of network intrusion detection systems includes receiving an alarm indicating a network intrusion may have occurred, identifying characteristics of the alarm, including at least an attack type and a target address, querying a target host associated with the target address for an operating system fingerprint, receiving the operating system fingerprint that includes the operating system type from the target host, comparing the attack type to the operating system type, and indicating whether the target host is vulnerable to the attack based on the comparison.
Public/Granted literature
- US20030212910A1 Method and system for reducing the false alarm rate of network intrusion detection systems Public/Granted day:2003-11-13
Information query