Invention Grant
- Patent Title: System and method for using timestamps to detect attacks
- Patent Title (中): 使用时间戳来检测攻击的系统和方法
-
Application No.: US11712260Application Date: 2007-02-27
-
Publication No.: US08578490B2Publication Date: 2013-11-05
- Inventor: Douglas B. Moran
- Applicant: Douglas B. Moran
- Applicant Address: US CA Mountain View
- Assignee: Symantec Corporation
- Current Assignee: Symantec Corporation
- Current Assignee Address: US CA Mountain View
- Agency: Wilmer Cutler Pickering Hale and Dorr LLP
- Main IPC: G06F11/30
- IPC: G06F11/30 ; G06F15/00 ; G06F17/30

Abstract:
A system and method are disclosed for detecting intrusions in a host system on a network. The intrusion detection system comprises an analysis engine configured to use continuations and apply forward- and backward-chaining using rules. Also provided are sensors, which communicate with the analysis engine using a meta-protocol in which the data packet comprises a 4-tuple. A configuration discovery mechanism locates host system files and communicates the locations to the analysis engine. A file processing mechanism matches contents of a deleted file to a directory or filename, and a directory processing mechanism extracts deallocated directory entries from a directory, creating a partial ordering of the entries. A signature checking mechanism computes the signature of a file and compares it to previously computed signatures. A buffer overflow attack detector compares access times of commands and their associated files. The intrusion detection system further includes a mechanism for checking timestamps to identify and analyze forward and backward time steps in a log file.
Public/Granted literature
- US20070157315A1 System and method for using timestamps to detect attacks Public/Granted day:2007-07-05
Information query