×

APPARATUS AND METHOD FOR IMPROVING DETECTION PERFORMANCE OF INTRUSION DETECTION SYSTEM

  • US 20150113646A1
  • Filed: 07/23/2014
  • Published: 04/23/2015
  • Est. Priority Date: 10/18/2013
  • Status: Active Grant
First Claim
Patent Images

1. An apparatus for improving detection performance of an intrusion detection system, comprising:

  • a transformed detected data generation unit for changing pieces of original detected data, detected based on current detection rules, to pieces of transformed detected data complying with a transformed detected data standard;

    a transformed detected data classification unit for classifying the pieces of transformed detected data by attack type, classifying pieces of transformed detected data for respective attack types by current detection rule, and classifying pieces of transformed detected data for respective detection rules into true positives/false positives;

    a transformed keyword tree generation unit for generating a true positive transformed keyword tree and a false positive transformed keyword tree, based on results of classification by the transformed detected data classification unit;

    a true positive path identification unit for generating a true positive node by comparing the true positive transformed keyword tree with the false positive transformed keyword tree, and for identifying a true positive path connecting a base node to the true positive node in the true positive transformed keyword tree; and

    a true positive detection pattern generation unit for generating a true positive detection pattern based on the identified true positive path.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×