×

Intrusion detection method and system

  • US 8,418,247 B2
  • Filed: 09/19/2008
  • Issued: 04/09/2013
  • Est. Priority Date: 09/19/2007
  • Status: Active Grant
First Claim
Patent Images

1. An intrusion detection method for detecting unauthorized use or abnormal activities of a targeted system of a network, comprising the steps of:

  • creating defined preconditions for each vulnerability related to the targeted system and/or for each attack that exploit one or several vulnerabilities;

    creating assurance references that correspond to said defined preconditions and a targeted perimeter;

    capturing data related to the targeted system;

    comparing said captured data with attack signatures to generate at least one security alert when said captured data and at least one attack signature match;

    capturing assurance metrics data from monitoring of the targeted perimeter;

    comparing said assurance metrics data with assurance references to generate assurance information when said assurance metrics data and at least one assurance reference match;

    retrieving the preconditions of said generated at least one security alert;

    checking when assurance information that corresponds to said preconditions has been retrieved;

    generating a verified security alarm when said generated at least one security alert and associated retrieved precondition match with at least one corresponding assurance information;

    filtering said generated at least one security alert when no match has been found between said associated retrieved preconditions and said at least one corresponding assurance information; and

    emitting a non verified security alert when no preconditions have been retrieved for said generated at least one security alert and/or no assurance reference corresponding to said preconditions has been defined.

View all claims
  • 3 Assignments
Timeline View
Assignment View
    ×
    ×