发明者
Young H Cho, William H Mangione-Smith
发表日期
2009/3/12
专利局
US
专利申请号
11918592
简介
The invention provides a method and apparatus for advanced network intrusion detection. The system uses deep packet inspection that can recognize languages described by context-free grammars. The system combines deep packet inspection with one or more grammar parsers (409A-409M). The invention can detect token streams (408) even when polymorphic. The system looks for tokens at multiple byte alignments and is capable of detecting multiple suspicious token streams (408). The invention is capable of detecting languages expressed in LL (I) or LR (I) grammar. The result is a system that can detect attacking code wherever it is located in the data stream (408).
引用总数
200820092010201120122013201420152016201720182019202020212022202332347171411971512542
学术搜索中的文章