Patent ReferencesPattern-oriented intrusion-detection system and method Telephonic switching system with automatic port assignment capability and method Method and means for preventing fraudulent use of telephone network Method and system for detecting intrusion into and misuse of a data processing system Facility for detecting intruders and suspect callers in a computer installation and a security system including such a facility Apparatus and method for providing a secure gateway for communication and data exchanges between networks Method and apparatus for automated network-wide surveillance and security breach intervention Detecting unauthorized network communication Method and apparatus for maintaining security in a packetized data communications network Network surveillance system InventorAssigneeApplicationNo. 268084 filed on 03/12/1999ExaminersPrimary: Hayes, Gail O.Assistant: Leaniny, Jeff Attorney, Agent or FirmInternational ClassG06F 011/30AbstractA computer-implemented intrusion detection system and method that monitors a computer system in real-time for activity indicative of attempted or actual access by unauthorized persons or computers. The system detects unauthorized users attempting to enter into a computer system by comparing user behavior to a user profile, detects events that indicate an unauthorized entry into the computer system, notifies a control function about the unauthorized users and events that indicate unauthorized entry into the computer system and has a control function that automatically takes action in response to the event. The user profiles are dynamically constructed for each computer user when the computer user first attempts to log into the computer system and upon subsequent logins, the user's profile is dynamically updated. By comparing user behavior to the dynamically built user profile, false alarms are reduced. The system also includes a log auditing function, a port scan detector and a session monitor function. | |