×

System and methods for adaptive model generation for detecting intrusions in computer systems

  • US 7,225,343 B1
  • Filed: 01/27/2003
  • Issued: 05/29/2007
  • Est. Priority Date: 01/25/2002
  • Status: Expired due to Term
First Claim
Patent Images

1. A system for detecting intrusions in the operation of a computer system comprising:

  • (a) a sensor configured to gather information regarding the operation of the computer system, to format the information in a data record having a predetermined format, and to transmit the data in the predetermined data format;

    (b) a data warehouse configured to receive the data record from the sensor in the predetermined data format, aggregate the data, store the data in a SQL database, and to store an intrusion detection model;

    (c) a detection model generator configured to request data records from the data warehouse in the predetermined data format, to generate the intrusion detection model based on said data records, and to transmit the intrusion detection model to the data warehouse according to the predetermined data format;

    (d) a detector configured to receive a data record in the predetermined data format from the sensor and to classify the data record in real-time as one of normal operation and an attack based on said intrusion detection model; and

    (e) a data analysis engine configured to request data records from the data warehouse according to the predetermined data format and to perform a data processing function on the data records.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×