Invention Grant
- Patent Title: Intrusion detection in communication networks
- Patent Title (中): 通信网络入侵检测
-
Application No.: US13517247Application Date: 2010-11-22
-
Publication No.: US08839430B2Publication Date: 2014-09-16
- Inventor: Marko Määttä , Tomi Räty , Tapio Taipale , Jouko Sankala
- Applicant: Marko Määttä , Tomi Räty , Tapio Taipale , Jouko Sankala
- Applicant Address: FI VTT
- Assignee: Teknologian Tutkimuskeskus VTT
- Current Assignee: Teknologian Tutkimuskeskus VTT
- Current Assignee Address: FI VTT
- Agent Mark M. Friedman
- Priority: FI20096394 20091223
- International Application: PCT/FI2010/051082 WO 20101122
- International Announcement: WO2011/077013 WO 20110630
- Main IPC: G06F11/00
- IPC: G06F11/00 ; G06F12/14 ; G08B23/00 ; H04L29/06 ; H04L12/26 ; H04L12/24

Abstract:
An intrusion detection arrangement for communication networks comprising a network activity observer configured to monitor network traffic by the related traffic elements, such as data packets, thereof and to establish traffic profiles relative to the monitored traffic elements, such as one profile per each monitored traffic element, a misuse detector configured to determine a first indication of a probability of the profiled traffic representing malicious activity through co-operation with a model repository comprising at least one model characterizing a known intrusion attack, an anomaly detector configured to determine, at least logically in parallel with the misuse detector, a second indication of a probability of the profiled traffic representing anomalous activity through cooperation with a model repository comprising at least one model characterizing legitimate network activity, and a classifier configured to operate on said first and second indications to generate a classification decision on the nature of the profiled traffic, wherein the applied classification space includes at least one class for legitimate traffic and at least one other class for other traffic such as malicious and/or anomalous traffic. A corresponding method is presented.
Public/Granted literature
- US20120278890A1 INTRUSION DETECTION IN COMMUNICATION NETWORKS Public/Granted day:2012-11-01
Information query