U.S. patents available from 1976 to present.
U.S. patent applications available from 2005 to present.

System and method for using login correlations to detect intrusions

Patent 7085936 Issued on August 1, 2006. Estimated Expiration Date: Icon_subject August 30, 2020. Estimated Expiration Date is calculated based on simple USPTO term provisions. It does not account for terminal disclaimers, term adjustments, failure to pay maintenance fees, or other factors which might affect the term of a patent.

Patent References

Distributed security auditing subsystem for an operating system
Patent #: 5032979
Issued on: 07/16/1991
Inventor: Hecht, et al.

Automated penetration analysis system and method
Patent #: 5485409
Issued on: 01/16/1996
Inventor: Gupta, et al.

Method and system for detecting intrusion into and misuse of a data processing system
Patent #: 5557742
Issued on: 09/17/1996
Inventor: Smaha, et al.

Dynamic software version auditor which monitors a process to provide a list of objects that are accessed
Patent #: 5574898
Issued on: 11/12/1996
Inventor: Leblang, et al.

Facility for detecting intruders and suspect callers in a computer installation and a security system including such a facility
Patent #: 5621889
Issued on: 04/15/1997
Inventor: Lermuzeaux, et al.

Data storage and protection system
Patent #: 5638509
Issued on: 06/10/1997
Inventor: Dunphy, et al.

Unification of directory service with file system services
Patent #: 5649194
Issued on: 07/15/1997
Inventor: Miller, et al.

Method and apparatus for defining data packet formats
Patent #: 5680585
Issued on: 10/21/1997
Inventor: Bruell

Apparatus for evaluating database query performance having libraries containing information for modeling the various system components of multiple systems
Patent #: 5724569
Issued on: 03/03/1998
Inventor: Andres

Method and apparatus for data authentication in a data communication environment
Patent #: 5757913
Issued on: 05/26/1998
Inventor: Bellare, et al.

More ...

Inventor

Assignee

Application

No. 09651854 filed on 08/30/2000

US Classes:

707/2, Access augmentation or optimizing703/23, EMULATION709/224Computer network monitoring

Examiners

Primary: Morse, Gregory
Assistant: Heneghan, Matthew

Attorney, Agent or Firm

International Classes

G06F 11/34
G06F 12/14
H04L 9/00

Abstract

A system and method are disclosed for detecting intrusions in a host system on a network. The intrusion detection system comprises an analysis engine configured to use continuations and apply forward- and backward-chaining using rules. Also provided are sensors, which communicate with the analysis engine using a meta-protocol in which the data packet comprises a 4-tuple. A configuration discovery mechanism locates host system files and communicates the locations to the analysis engine. A file processing mechanism matches contents of a deleted file to a directory or filename, and a directory processing mechanism extracts deallocated directory entries from a directory, creating a partial ordering of the entries. A signature checking mechanism computes the signature of a file and compares it to previously computed signatures. A buffer overflow attack detector compares access times of commands and their associated files. The intrusion detection system further includes a mechanism for checking timestamps to identify and analyze forward and backward time steps in a log file.

Other References

  • Frisch, “Essential System Administration,” 1995, pp. 250 and 262-265.
  • Rebecca Bace, Introduction to Intrusion Detection Assesment, no date, for System and Network Security Management.
  • Gene H. Kim and Eugene H. Spafford, Writing, Supporting and Evaluating Tripwire: A Publically Available Security Tool, Mar. 12, 1994, Purdue Technical Report; Purdue University.
  • Douglas B. Moran et al., Derbi: Diagnosis, Explanation and Recovery From Break-Ins, no date, Artificial Intelligence Center SRI International.
  • Mabry Tyson, Ph.D., Explaining and Recovering From Computer Break-Ins, Jan. 12, 2001, SRI International.
  • Aleph One, Smashing the Stack for fun and Profit, no date, vol. Seven, Issue Forty-Nine; File 14 of 16 of BugTraq, r00t, and Underground.Org.
  • Donald C. Latham, Department of Defense Trusted Computer System Evaluation Criteria, Dec. 1985, Department of Defense Standard.
  • James P. Anderson Co., Computer Security Threat Monitoring and Surveillance, Feb. 26, 1980, Contract 79F296400.
  • Teresa F. Hunt et al., A Real-Time Intrusion-Detection Expert System (IDES), Feb. 28, 1992, SRI International Project 6784.
  • Lawrence Halme, Teresa Lunt, and J. Van Horne, Automated Analysis of Computer System Audit Trails for Security Purposes. Proceedings of the National Computer Security Conference, Washington, D.C., 1986.
  • Teresa Lunt, Automated Audit Trail Analysis and Intrusion Detection: A Survey. Proceedings of the Eleventh National Computer Security Conference, Washington, D.C., Oct. 1988.
  • Teresa F. Lunt, Ann Tamaru, Fred Gilham, R. Jagannathan, Peter G. Neumann, Caveh Jalali, IDES: A Progress Report. Proceedings of the Sixth Annual Computer Security Applications Conference, Tucson, AZ, Dec. 1990.
PatentsPlus Images
Enhanced PDF formats
loading...
PatentsPlus: add to cart
PatentsPlus: add to cartSearch-enhanced full patent PDF image
$9.95more info
PatentsPlus: add to cart
PatentsPlus: add to cartIntelligent turbocharged patent PDFs with marked up images
$18.95more info
 
Sign InRegister
Username  
Password   
forgot password?