IP Library Granted Patent US 7,260,843
Granted Patent B2
US 7,260,843 · App. 10/179,008 · Granted Aug 21, 2007

Intrusion detection method and system

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,260,843
App. No.
10/179,008
Granted
Aug 21, 2007
Kind
B2
Abstract

An intrusion detection system employs a pointer fingerprint method for detecting attempted or successful intrusions into an information system or network. In a pointer fingerprint method, the specific stream of bits searched from the traffic streams is a pointer or part of it that must be included in all working buffer overflow (bof) attacks. This makes it possible to detect also the previously unknown bof attacks.

Claims (35)

1. A method of detecting intrusions to a data system, said method comprising:

searching for at least one predefined pattern in a traffic stream, said predefined pattern being part of at least one pointer,

detecting a potential attack, if said at least one predefined pattern is found in the traffic stream,

said at least one predefined pattern comprising a predetermined stream of bits from a return address space of an operating system buffer to detect a buffer overflow attack against said operating system buffer.

2. A method according to claim 1 , wherein said at least one pointer comprises a stack pointer.

3. A method according to claim 1 , wherein said at least one pointer comprises a library of c (libc) function pointer or a pointer to a Global Offset Table (GOT).

4. A method according to claim 1 , 2 or 3 , comprising

determining parts of said traffic which are not in accordance with a specific protocol used

searching for said at least part of said at least one pointer in said determined part of said traffic.

5. A method according to claim 1 , 2 or 3 , comprising searching for said part of said at least one pointer only in specific types of data packets or data streams according to a specific protocol which do not contain pointers in accordance with the specific protocol.

6. A method according to claim 1 , 2 or 3 , comprising

searching for said part of said at least one pointer in all traffic,

if a pointer fingerprint is found, analyzing whether the presence of a pointer in the specific point in the traffic is allowed or not, and

if the presence of the pointer is not allowed, an attack is assumed to be detected.

7. A method of detecting intrusion to a data system, said method comprising:

searching for part of at least one stack pointer in a traffic stream,

detecting a potential attack, if said part of said at least one stack pointer is found in the traffic stream,

said part of at least one stack pointer comprising a predetermined stream of bits from a return address space of an operating system buffer to detect a buffer overflow attack against said operating system buffer.

8. A computer-readable medium, containing a computer software which causes the computer to execute a process comprising:

searching for at least one predefined pattern in a traffic stream, said predefined pattern being part of at lest one pointer,

detecting a potential attack, if said at least one predefined pattern is found in the traffic stream,

said at least one predefined pattern comprising a predetermined stream of bits from a return address space of an operating system buffer to detect a buffer overflow attack against said operating system buffer.

9. A computer-readable medium, containing a computer software which causes the computer to execute a process comprising;

searching for part of at least one stack pointer in a traffic stream,

detecting a potential attack, if said part of said at least one stack pointer is found in the traffic stream,

said part of at least one stack pointer comprising a predetermined stream of bits from a return address space of an operating system buffer to detect a buffer overflow attack against said operating system buffer.

10. An intrusion detection system, said system comprising:

means for searching for at least one predefined pattern in a traffic stream,

means for detecting a potential attack, if said at least one predefined pattern is found in the traffic stream,

wherein said at least one predefined pattern is part of at least one pointer,

said at least one predefined pattern comprising a predetermined stream of bits from a return address space of an operating system buffer to detect a buffer overflow attack against said operating system buffer.

11. An intrusion detection system, said system comprising:

means for searching for at least one predefined pattern in a traffic stream,

means for detecting a potential attack, if said at least one predefined pattern is found in the traffic stream,

wherein said at least one predefined pattern is part of at least one stack pointer, and said at least one predefined pattern comprises a predetermined stream of bits from a return address space of an operating system buffer to detect a buffer overflow attack against said operating system buffer.

Assignments (9)
RELEASE OF SECURITY INTEREST Recorded Apr 2, 2025
From: UBS AG, STAMFORD BRANCH
To: FORCEPOINT, LLC; BITGLASS, LLC
Reel/Frame 070706/0263 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 18, 2021
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: FORCEPOINT LLC
Reel/Frame 056272/0475 →
CHANGE OF NAME Recorded May 10, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056183/0265 →
PATENT SECURITY AGREEMENT Recorded Jan 20, 2021
From: REDOWL ANALYTICS, INC.; FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 055052/0302 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: FORCEPOINT LLC
Reel/Frame 055452/0220 →
PATENT SECURITY AGREEMENT SUPPLEMENT Recorded Feb 12, 2018
From: FORCEPOINT LLC
To: RAYTHEON COMPANY
Reel/Frame 045312/0043 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2017
From: FORCEPOINT FINLAND OY
To: FORCEPOINT LLC
Reel/Frame 043156/0547 →
CHANGE OF NAME Recorded Apr 15, 2016
From: WEBSENSE FINLAND OY
To: FORCEPOINT FINLAND OY
Reel/Frame 038447/0441 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 25, 2016
From: STONESOFT OY DBA STONESOFT CORPORATION
To: WEBSENSE FINLAND OY
Reel/Frame 037828/0385 →