Invention Grant
- Patent Title: Source/destination operating system type-based IDS virtualization
- Patent Title (中): 源/目标操作系统类型的IDS虚拟化
-
Application No.: US10832588Application Date: 2004-04-27
-
Publication No.: US07904960B2Publication Date: 2011-03-08
- Inventor: Ravishankar Ganesh Ithal
- Applicant: Ravishankar Ganesh Ithal
- Applicant Address: US CA San Jose
- Assignee: Cisco Technology, Inc.
- Current Assignee: Cisco Technology, Inc.
- Current Assignee Address: US CA San Jose
- Agency: BainwoodHuang
- Main IPC: H04L9/00
- IPC: H04L9/00

Abstract:
Systems and methods for virtualizing network intrusion detection system (IDS) functions based on each packet's source and/or destination host computer operating system (OS) type and characteristics are described. Virtualization is accomplished by fingerprinting each packet to determine the packet's target OS and then vetting each packet in a virtual IDS against a reduced set of threat signatures specific to the target OS. Each virtual IDS, whether operating on a separate computer or operating as a logically distinct process or separate thread running on a single computer processor, may also operate in parallel with other virtual IDS processes. IDS processing efficiency and speed are greatly increased by the fact that a much smaller subset of threat signature universe is used for each OS-specific packet threat vetting operation.
Public/Granted literature
- US20080289040A1 Source/destination operating system type-based IDS virtualization Public/Granted day:2008-11-20
Information query