WO0116664A1

System and method for detecting computer intrusions

Abstract

A system and method are disclosed for detecting intrusions in a host system on a network. The intrusion detection system comprises an analysis engine configured to use continuations and apply forward- and backward-chaining using rules. Also provided are sensors, which communicate with the analysis engine using a meta-protocol in which the data packet comprises a 4-tuple. A configuration discovery mechanism locates host system files and communicates the locations to the analysis engine. A file processing mechanism matches contents of a deleted file to a directory or filename, and a directory processing mechanism extracts deallocated directory entries from a directory, creating a partial ordering of the entries. A signature checking mechanism computes the signature of a file and compares it to previously computed signatures. A buffer overflow attack detector compares access times of commands and their associated files. The intrusion detection system further includes a mechanism for checking timestamps to identify and analyze forward and backward time steps in a log file.

WO0116664A1, drawing sheet 1
Sheet 1 of 11

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

17 claims: 3 independent, 14 dependent

  1. 1
    CLAIMS 1. A system for detecting intrusion on a host, comprising:a) a source of rules;b) a source of facts;and c) an analysis engine in communication with the source of rules and source of facts, configured to apply forward- and backward-chaining using facts from the source of facts and rules from the source of rules.
  2. 16
    A method for detecting intrusions on a host, comprising the steps of:a) providing a source of rules and a source of facts;b) forward- and backward-chaining using facts from the source of facts and rules from the source of rules.
  3. 17
    A computer program product for detecting intrusions on a host, the computer program product being embodied in a computer readable medium having machine readable code embodied therein for performing the steps of:a) providing a source of rules and a source of facts;b) forward- and backward-chaining using facts from the source of facts and rules from the source of rules.