×

System and methods for adaptive model generation for detecting intrusion in computer systems

  • US 20130031633A1
  • Filed: 09/10/2012
  • Published: 01/31/2013
  • Est. Priority Date: 01/25/2002
  • Status: Active Grant
First Claim
Patent Images

1. A system for detecting intrusions in the operation of a computer system comprising:

  • (a) a sensor configured to gather information regarding the operation of the computer system, to format the information in a data record, and to transmit the data record;

    (b) one or more databases configured to receive the data record from the sensor, to store the data record, and to store an intrusion detection model;

    (c) a detection model generator configured to request data records from the one or more databases, to generate the intrusion detection model based on said data records, and to transmit the intrusion detection model to the one or more databases;

    (d) a detector configured to receive a data record from the sensor and to classify the data record in real-time as one of normal operation and an attack based on said intrusion detection model;

    (e) a data analysis engine configured to request data records from the one or more databases and to perform a data processing function on the data records; and

    (f) a detection model distributor configured to receive said intrusion detection model from the one or more databases and to transmit the detection model to at least one detector.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×