Probabilistic alert correlation

Number of patents in Portfolio can not be more than 2000

United States of America Patent

PATENT NO 7917393
APP PUB NO 20020059078A1
SERIAL NO

09944788

Stats

ATTORNEY / AGENT: (SPONSORED)

Importance

Loading Importance Indicators... loading....

Abstract

See full text

This invention uses probabilistic correlation techniques to increase sensitivity, reduce false alarms, and improve alert report quality in intrusion detection systems. In one preferred embodiment, an intrusion detection system includes at least two sensors to monitor different aspects of a computer network, such as a sensor that monitors network traffic and a sensor that discovers and monitors available network resources. The sensors are correlated in that the belief state of one sensor is used to update or modify the belief state of another sensor. In another embodiment of this invention, probabilistic correlation techniques are used to organize alerts generated by different sensors in an intrusion detection system. By comparing features of each new alert with features of previous alerts, rejecting a match if a feature fails to meet or exceed a minimum similarity value, and adjusting the comparison by an expectation that certain feature values will or will not match, the alerts can be grouped in an intelligent manner.

Loading the Abstract Image... loading....

First Claim

See full text

Family

Loading Family data... loading....

Patent Owner(s)

Patent OwnerAddress
SRI INTERNATIONAL INCMENLO PARK CA

International Classification(s)

Inventor(s)

Inventor Name Address # of filed Patents Total Citations
Skinner, Keith Sunnyvale, US 5 288
Valdes, Alfonso De Jesus San Carlos, US 5 456

Cited Art Landscape

Load Citation

Patent Citation Ranking

Forward Cite Landscape

Load Citation