SYSTEM AND METHOD FOR USING TIMESTAMPS TO DETECT ATTACKS

Patent №

US 7,203,962

Granted

2007-04-10

Filed 2000

Owner

RECOURSE TECHNOLOGIES, INC.

+1 more

Lab

AI components

1

hardware

Assignment

Recorded

Dataset

AIPD

2023_r1 edition

Application

09654347

A system and method are disclosed for detecting intrusions in a host system on a network. The intrusion detection system comprises an analysis engine configured to use continuations and apply forward- and backward-chaining using rules. Also provided are sensors, which communicate with the analysis engine using a meta-protocol in which the data packet comprises a 4-tuple. A configuration discovery mechanism locates host system files and communicates the locations to the analysis engine. A file processing mechanism matches contents of a deleted file to a directory or filename, and a directory processing mechanism extracts deallocated directory entries from a directory, creating a partial ordering of the entries. A signature checking mechanism computes the signature of a file and compares it to previously computed signatures. A buffer overflow attack detector compares access times of commands and their associated files. The intrusion detection system further includes a mechanism for checking timestamps to identify and analyze forward and backward time steps in a log file.

AI hardwareH04L 63/1416G06F 21/52G06F 21/552H04L 63/1425G06F 2221/2151H04L 2463/121

AI classification

AI hardware0.84
Knowledge representation0.11
Natural language0.01
Vision0.00
Machine learning0.00
Evolutionary computation0.00
Speech0.00
Planning0.00

Ownership

RECOURSE TECHNOLOGIES, INC.

assignment · 113460746

SYMANTEC CORPORATION

assignment · 137560291

© 2026 NYSGPT2525 LLC