Invention Grant
US07904960B2 Source/destination operating system type-based IDS virtualization 有权
源/目标操作系统类型的IDS虚拟化

Source/destination operating system type-based IDS virtualization
Abstract:
Systems and methods for virtualizing network intrusion detection system (IDS) functions based on each packet's source and/or destination host computer operating system (OS) type and characteristics are described. Virtualization is accomplished by fingerprinting each packet to determine the packet's target OS and then vetting each packet in a virtual IDS against a reduced set of threat signatures specific to the target OS. Each virtual IDS, whether operating on a separate computer or operating as a logically distinct process or separate thread running on a single computer processor, may also operate in parallel with other virtual IDS processes. IDS processing efficiency and speed are greatly increased by the fact that a much smaller subset of threat signature universe is used for each OS-specific packet threat vetting operation.
Public/Granted literature
Information query
Patent Agency Ranking
0/0