IP Library Granted Patent US 7,085,936
Granted Patent B1
US 7,085,936 · App. 09/651,854 · Granted Aug 1, 2006

System and method for using login correlations to detect intrusions

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,085,936
App. No.
09/651,854
Granted
Aug 1, 2006
Kind
B1
Abstract

A system and method are disclosed for detecting intrusions in a host system on a network. The intrusion detection system comprises an analysis engine configured to use continuations and apply forward- and backward-chaining using rules. Also provided are sensors, which communicate with the analysis engine using a meta-protocol in which the data packet comprises a 4-tuple. A configuration discovery mechanism locates host system files and communicates the locations to the analysis engine. A file processing mechanism matches contents of a deleted file to a directory or filename, and a directory processing mechanism extracts deallocated directory entries from a directory, creating a partial ordering of the entries. A signature checking mechanism computes the signature of a file and compares it to previously computed signatures. A buffer overflow attack detector compares access times of commands and their associated files. The intrusion detection system further includes a mechanism for checking timestamps to identify and analyze forward and backward time steps in a log file.

Claims (8)

1. A method for detecting intrusions on a host, comprising:

collecting information from a logfile located on the host; and

analyzing the logfile, including by using a time decay function to compute a suspicion value for an entry in the logfile including by computing a probability for an end of a session with which the entry is associated.

2. A method as recited in claim 1 , wherein the logfile is sulog and the session is an su session.

3. A computer program product for detecting intrusions on a host, the computer program product being embodied in a computer readable medium and comprising computer instructions for:

collecting information from a logfile located on the host; and

analyzing the logfile, including by using a time decay function to compute a suspicion value for an entry in the logfile including by using the time decay function to compute a probability for an end of a session with which the entry is associated.

4. A computer program product as recited in claim 3 , wherein the logfile is sulog and the session is an su session.

Assignments (8)
NOTICE OF SUCCESSION OF AGENCY (REEL 050926 / FRAME 0560) Recorded Sep 13, 2022
From: JPMORGAN CHASE BANK, N.A.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 061422/0371 →
SECURITY AGREEMENT Recorded Sep 13, 2022
From: NORTONLIFELOCK INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062220/0001 →
SECURITY AGREEMENT Recorded Nov 4, 2019
From: SYMANTEC CORPORATION; BLUE COAT LLC; LIFELOCK, INC,; SYMANTEC OPERATING CORPORATION
To: JPMORGAN, N.A.
Reel/Frame 050926/0560 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 24, 2003
From: RECOURSE TECHNOLOGIES, INC.
To: SYMANTEC CORPORATION
Reel/Frame 013778/0216 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 10, 2003
From: RECOURSE ACQUISITION CORP.; RECOURSE TECHNOLOGIES, INC.
To: RECOURSE TECHNOLOGIES, INC.
Reel/Frame 013649/0170 →
REASSIGNMENT AND RELEASE OF SECURITY INTEREST Recorded Aug 14, 2002
From: COMERICA BANK-CALIFORNIA, AS SUCCESSOR IN INTEREST TO IMPERIAL BANK
To: REOUCRSE TECHNOLOGIES, INC.
Reel/Frame 013199/0934 →
SECURITY AGREEMENT Recorded Feb 8, 2001
From: RECOURSE TECHNOLOGIES, INC.
To: IMPERIAL BANK
Reel/Frame 011510/0802 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 5, 2000
From: MORAN, DOUGLAS B.
To: RECOURSE TECHNOLOGIES, INC.
Reel/Frame 011350/0656 →