Invention Grant
- Patent Title: Compound attack detection in a computer network
- Patent Title (中): 计算机网络中的复合攻击检测
-
Application No.: US11045572Application Date: 2005-01-27
-
Publication No.: US08209756B1Publication Date: 2012-06-26
- Inventor: Kowsik Guruswamy , Siu-Wang Leung
- Applicant: Kowsik Guruswamy , Siu-Wang Leung
- Applicant Address: US CA Sunnyvale
- Assignee: Juniper Networks, Inc.
- Current Assignee: Juniper Networks, Inc.
- Current Assignee Address: US CA Sunnyvale
- Agency: Shumaker & Sieffert, P.A.
- Main IPC: G06F11/30
- IPC: G06F11/30 ; G06F17/30

Abstract:
An intrusion detection and prevention (IDP) device includes an attack detection module and a forwarding component. The attack detection module applies a compound attack definition to a packet flow of a computer network to determine whether the packet flow includes at least one pattern and at least one protocol anomaly. The forwarding component selectively discards the packet flow based on the determination. The IDP device may further include a reassembly module to form application-layer communications from the packet flows, and a plurality of protocol-specific decoders to process the application-layer communications to extract application-layer elements and detect protocol anomalies.
Information query