Patent · US Expired

Systems and methods for detecting network intrusions

US7500266B1 · kind B1 · utility

20Cited by
2References
24Claims
0Family size

Assignees

Inventors

Key dates

Filing dateDec 3, 2002
Grant dateMar 3, 2009
Priority date
Expiry dateSep 19, 2024

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L63/1416
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

A device (120) processes traffic in a network. The device (120) obtains information corresponding to an activity between a group of source devices and one or more services of destination devices, measures, for each of the group of source devices, a behavior of the source activity in terms of independence and uniformity of access to the one or more services, and determines, for each of the group of source devices, whether the source activity includes probing based on the measured behavior. The device (120) also determines, for each of the group of source devices, a similarity factor representing a similarity between the source activity of one of the group of source devices and another of the group of source devices, compares the similarity factors for each pair of source devices to a threshold, and groups source devices when the similar factor for those source devices are below the threshold.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.