作者: Craig H. Rowland
DOI:
关键词: Monitor function 、 Real-time computing 、 Session (web analytics) 、 Intrusion detection system 、 Event (computing) 、 Port scan 、 Function (engineering) 、 User profile 、 Computer science
摘要: A computer-implemented intrusion detection system and method that monitors a computer in real-time for activity indicative of attempted or actual access by unauthorized persons computers. The detects users attempting to enter into comparing user behavior profile, events indicate an entry the system, notifies control function about has automatically takes action response event. profiles are dynamically constructed each when first attempts log upon subsequent logins, user's profile is updated. By built false alarms reduced. also includes auditing function, port scan detector session monitor function.