×

System and method for using login correlations to detect intrusions

  • US 7,085,936 B1
  • Filed: 08/30/2000
  • Issued: 08/01/2006
  • Est. Priority Date: 08/30/1999
  • Status: Expired due to Term
First Claim
Patent Images

1. A method for detecting intrusions on a host, comprising:

  • collecting information from a logfile located on the host; and

    analyzing the logfile, including by using a time decay function to compute a suspicion value for an entry in the logfile including by computing a probability for an end of a session with which the entry is associated.

View all claims
  • 8 Assignments
Timeline View
Assignment View
    ×
    ×