Patent · US Expired

Intrusion detection strategies for hypertext transport protocol

US7496962B2 · kind B2 · utility

35Cited by
44References
23Claims
0Family size

Assignee

Inventors

Key dates

Filing dateSep 29, 2004
Grant dateFeb 24, 2009
Priority date
Expiry dateFeb 15, 2026

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L63/1408
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

A hypertext transport protocol (HTTP) inspection engine for an intrusion detection system (IDS) includes an HTTP policy selection component, a request universal resource identifier (URI) discovery component, and a URI normalization module. The HTTP policy selection component identifies an HTTP intrusion detection policy using a packet. The request URI discovery component locates a URI within the packet. The URI normalization module decodes an obfuscation within the URI. In another embodiment, a packet transmitted on the network is intercepted. The packet is parsed. An Internet protocol (IP) address of the packet is identified. An HTTP intrusion detection policy for a network device is determined. A URI is located in the packet. A pattern from an intrusion detection system rule is compared to the located URI. In another embodiment, an IDS includes a packet acquisition system, network and transport reassembly modules, an HTTP inspection engine, a detection engine, and a logging system.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.