×

Host-based systematic attack detection tool

  • US 20030154396A1
  • Filed: 08/30/2001
  • Published: 08/14/2003
  • Est. Priority Date: 08/30/2001
  • Status: Active Grant
First Claim
Patent Images

1. A method for detecting systematic attacks and unauthorized attempts to access a host computer, said host computer having an event list containing time-stamped records for each attempt to login or logon to the host computer, said records including user detail information such as a user name, said event list having an earliest event and a latest event with the time there between being a scan time, said method comprising the steps of:

  • establishing a float period length having a finite time duration;

    establishing a float period at an initial position, said float period having a start time and an end time, said end time being equal to said start time plus said float period length, wherein said start time is initially equal to a time stamp value of said earliest event in said event list;

    counting a number of events in said event list which fall within said current float period;

    responsive to said count exceeding a threshold, producing a violation message and jumping said float period by setting said start time to be equal to a time stamp value of an event in said event list immediately following said float period end time, otherwise advancing said float period by a single event by setting said start time to a time stamp value of an event in said event list immediately following said start time; and

    iterating said steps of counting, producing a violation message and jumping said float period and single-event advancing of said float period until said float period end time exceeds a time stamp value of said latest event in said event list.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×