×

Intrusion detection system using self-organizing clusters

DC
  • US 7,017,186 B2
  • Filed: 07/30/2002
  • Issued: 03/21/2006
  • Est. Priority Date: 07/30/2002
  • Status: Expired due to Term
First Claim
Patent Images

1. A machine readable storage having stored thereon a computer program for detecting network intrusions, said computer program comprising a routine set of instructions which when executed cause the machine to perform the steps of:

  • monitoring network traffic passing across a network communications path;

    extracting network packets from said passing traffic;

    storing individual components of said network packets in a database;

    constructing multi-dimensional vectors from at least two of said stored individual components and applying at least one multi-variate analysis to said constructed multi-dimensional vectors, said at least one multi-variate analysis producing a corresponding output set;

    establishing a correlation between individual output sets based upon a selected metric to identify anomalous behavior; and

    ,classifying said anomalous behavior as one of a network fault or a network attack.

View all claims
  • 8 Assignments
Timeline View
Assignment View
    ×
    ×