会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 2. 发明申请
    • Intrusion detection via high dimensional vector matching
    • 通过高维矢量匹配的入侵检测
    • US20080120720A1
    • 2008-05-22
    • US11601864
    • 2006-11-17
    • Jinhong GuoDaniel WeberStephen JohnsonIl-Pyung Park
    • Jinhong GuoDaniel WeberStephen JohnsonIl-Pyung Park
    • G06F21/00
    • G06F21/552
    • A method is provided for detecting intrusions to a computing environment. The method includes: monitoring system calls made to an operating system during a defined period of time; evaluating the system calls made during the defined time period in relation to system calls made during known intrusions; and evaluating the temporal sequence in which system calls were made during the defined time period when the system calls made match the system calls made during a known intrusion. If a potential intrusion is detected at this stage, then a more complicated detection scheme may be performed by a second detection scheme. For instance, the second detection scheme may assess the temporal sequence in which the system calls were made and/or the system files accessed by the system calls.
    • 提供了一种用于检测对计算环境的入侵的方法。 该方法包括:在定义的时间段内监视对操作系统的系统调用; 评估在定义的时间段内与在已知入侵期间进行的系统呼叫相关的系统呼叫; 并且在系统调用所规定的时间段期间评估进行系统调用的时间序列,使得在已知入侵期间进行的系统呼叫匹配。 如果在该阶段检测到潜在入侵,则可以通过第二检测方案来执行更复杂的检测方案。 例如,第二检测方案可以评估系统调用的时间顺序和/或系统调用所访问的系统文件。
    • 5. 发明申请
    • Dynamic update of pluggable modules using a reference manager
    • 使用引用管理器动态更新可插拔模块
    • US20050257093A1
    • 2005-11-17
    • US10829096
    • 2004-04-21
    • Stephen JohnsonJinhong GuoIl-Pyung Park
    • Stephen JohnsonJinhong GuoIl-Pyung Park
    • G06F9/445G06F11/00
    • G06F8/656
    • A method is provided for replacing a loadable software module in an operating system. The method include: maintaining a reference count for a loadable software module associated with a kernel of the operating system; linking a replacement software module for the loadable software module into the kernel of the operating system; receiving a resource request for the loadable software module after the replacement software module is linked into the kernel; and directing the resource request for the loadable software module to the replacement software module. The method may further include unlinking the loadable software module from the kernel of the operating system when there are no longer any active references to the loadable module.
    • 提供了一种用于替换操作系统中的可加载软件模块的方法。 该方法包括:维护与操作系统的内核相关联的可加载软件模块的引用计数; 将可加载软件模块的替换软件模块链接到操作系统的内核; 在替换软件模块链接到内核之后,接收可加载软件模块的资源请求; 并将可加载软件模块的资源请求定向到替换软件模块。 该方法还可以包括当不再对可加载模块的任何活动引用时,将可加载的软件模块与操作系统的内核断开连接。