Invention Grant
- Patent Title: Computer network intrusion detection system and method
- Patent Title (中): 计算机网络入侵检测系统及方法
-
Application No.: US11916373Application Date: 2006-05-31
-
Publication No.: US08272054B2Publication Date: 2012-09-18
- Inventor: Jean-Jacques Dequevy
- Applicant: Jean-Jacques Dequevy
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agency: Schmeiser, Olsen & Watts
- Agent John Pivnichny
- Priority: EP05300457 20050606
- International Application: PCT/EP2006/062766 WO 20060531
- International Announcement: WO2006/131475 WO 20061214
- Main IPC: H04L29/06
- IPC: H04L29/06

Abstract:
A method and system for identifying an attacker device attempting an intrusion into a TCP/IP protocol based network that includes a managed device and a security event log. The managed device detects an incoming TCP/IP connection by the attacker device to the network. TCP/IP information relating to the attacker device is extracted from a TCP/IP stack of the managed device. It is ascertained that a port number of the incoming TCP/IP connection is identical to a predefined port number. A performed process includes determining that the incoming TCP/IP connection is a Net BIOS connection that has created an invalid logon by the attacker device. Event log information, which is associated with the detected incoming TCP/IP connection, is retrieved from the security event log. A generated report is generated and stored in a database of the network. The report includes the extracted TCP/IP information and the retrieved event log information.
Public/Granted literature
- US20080209541A1 Computer Network Intrusion Detection System and Method Public/Granted day:2008-08-28
Information query