×

Modular system for detecting, filtering and providing notice about attack events associated with network security

  • US 7,152,242 B2
  • Filed: 09/11/2002
  • Issued: 12/19/2006
  • Est. Priority Date: 09/11/2002
  • Status: Active Grant
First Claim
Patent Images

1. A computer-readable medium having computer-executable instructions for performing intrusion detection of a computer network having at least one host computer coupled thereto, said computer-readable medium being loadable on the at least one host computer, said computer-readable medium comprising:

  • an array of event processing means wherein each one of said event processing means runs concurrently without impeding each other'"'"'s performance, said array of event processing means monitoring resources on the at least one host computer or monitoring activity forwarded to the at least one host computer via the computer network and generating event data corresponding to said monitoring;

    an event filter engine for filtering all event data from said array of event processing means, said event filter engine either altering the contents of the event data to form filtered event data or discarding the event data, said event filter engine altering the contents of the event data by altering an event data name based on a source network address related to said event data, said event filter engine comprising a plurality of configured modules and wherein said event filter engine passes all event data through said configured modules serially; and

    an event alerting engine for generating alerts based on said filtered event data or forwarding said filtered event data to a destination, and wherein said event alerting engine comprises a second plurality of configured modules and wherein each of said second plurality of configured modules receives all of said filtered event data.

View all claims
  • 13 Assignments
Timeline View
Assignment View
    ×
    ×