Intrusion detection

CL 726 SC 23
7043759 Architecture to thwart denial of service attacks
May-9-2006 A system architecture for thwarting denial of service attacks on a victim data center is described. The system includes a first plurality of monitors that monitor network traffic flow through the network....
7043757 System and method for malicious code detection
May-9-2006 A system for malicious code detection includes a front-end processor, multiple scanning computer systems, and a detection management system. During operation, the multiple scanning computer systems scan...
7043756 Method and apparatus for detecting denial-of-service attacks using kernel execution profiles
May-9-2006 One embodiment of the present invention provides a system that detects denial-of-service attacks by using an execution profile for a kernel of a server computer system. The system produces a run-time execution...
7039953 Hierarchical correlation of intrusion detection events
May-2-2006 A method, computer program product, and apparatus for presenting data about security-related events that puts the data into a concise form is disclosed. Events are abstracted into a set data-type. Sets...
7039950 System and method for network quality of service protection on security breach detection
May-2-2006 A system, method and computer program product for ensuring the quality of services being provided by a protected network of computers during an ongoing security breach is provided. The quality of the services...
7028338 System, computer program, and method of cooperative response to threat to domain security
Apr-11-2006 A system, computer program, and method of providing an automatic cooperative response ability to all members of a domain in light of a detected threat or other suspicious activity, such as, for example,...
7024694 Method and apparatus for content-based instrusion detection using an agile kernel-based auditor
Apr-4-2006 One embodiment of the present invention provides content-based intrusion detection for a computer system by using an agile kernel-based auditing system. This auditing system operates by receiving an audit...
7024565 Method and apparatus to detect circuit tampering
Apr-4-2006 A circuit includes a capacitor formed with a dielectric including the dielectric encasing elements of the circuit. A detector detects changes in the capacitance of the capacitor.
7024548 Methods and apparatus for auditing and tracking changes to an existing configuration of a computerized device
Apr-4-2006 A change controller application, process and system tracks modification to a configuration of a computerized device by receiving a change request indicating a requested change to an existing configuration...
7017187 Method and system for file blocking in an electronic messaging system
Mar-21-2006 The invention provides a method and system for quickly and preemptively controlling the outbreak of destructive software applications sent in an electronic messaging system. Such system and method provide...
7017186 Intrusion detection system using self-organizing clusters
Mar-21-2006 An intrusion detection system (IDS). An IDS which has been configured in accordance with the present invention can include a traffic sniffer for extracting network packets from passing network traffic;...
7017185 Method and system for maintaining network activity data for intrusion detection
Mar-21-2006 A method and system for maintaining network activity data for intrusion detection includes storing data representative of network activity in datasets. The datasets include root datasets each having a...
7013483 Method for emulating an executable code in order to detect maliciousness
Mar-14-2006 The present invention is directed to a method for emulating an executable code, whether it is a human-readable code (e.g., macro and script) or a compiled code (e.g. Windows executable). At the design...
7010807 System and method for network virus protection
Mar-7-2006 A system and method for virus protection of computers on a local area network (LAN) is disclosed. The LAN's anti-virus policy is programmed into the firewall, or other Internet access module, which applies...
7007302 Efficient management and blocking of malicious code and hacking attempts in a network environment
Feb-28-2006 A system, method and computer program product are provided for preventing an outbreak of malicious code. First, malicious code is identified at a local location on a network. Information relating to the...
7007301 Computer architecture for an intrusion detection system
Feb-28-2006 The present application is directed to a host-based IDS on an HP-UX intrusion detection system that enhances local host-level security within the network. It should be understood that the present invention...
7007299 Method and system for internet hosting and security
Feb-28-2006 The present invention relates to a system and method for providing security to Internet hosting sites and mitigating electronic attacks against such sites. The system and method of the present invention...
6996843 System and method for detecting computer intrusions
Feb-7-2006 A system and method are disclosed for detecting intrusions in a host system on a network. The intrusion detection system comprises an analysis engine configured to use continuations and apply forward-...
6993660 System and method for performing efficient computer virus scanning of transient messages using checksums in a distributed computing environment
Jan-31-2006 A system and method for performing efficient computer virus scanning of transient messages using checksums in a distributed computing environment is described. An incoming message is intercepted at a network...
6993132 System and method for reducing fraud in a digital cable network
Jan-31-2006 A digital cable network architecture includes hosts that include a receiver with a hash function generator that calculates hash values based on a hash function and data from memory blocks in the receiver....
6986161 Mobile ad-hoc network with intrusion detection features and related methods
Jan-10-2006 A mobile ad-hoc network (MANET) may include a plurality of nodes for transmitting data therebetween and a policing node. The policing node may detect intrusions into the MANET by monitoring transmissions...
6981280 Intelligent network scanning system and method
Dec-27-2005 A system, method and computer program product are provided for scanning data. Initially, data is received at a network element. Thereafter, a load on the network element is identified. The data is then...
6981279 Method and apparatus for replicating and analyzing worm programs
Dec-27-2005 A system and a method are disclosed for dynamically analyzing software, some of whose potentially-important behaviors (such as worm-like behavior) may only be displayed when the software is executed in...