SYSTEM AND METHOD FOR NEAR-REAL TIME NETWORK ATTACK DETECTION, AND SYSTEM AND METHOD FOR UNIFIED DETECTION VIA DETECTION ROUTING
Patent №
US 8,677,486
Granted
2014-03-18
Filed 2011
Owner
SOURCEFIRE, INC.
Lab
—
AI components
1
hardware
Assignment
Recorded
Dataset
AIPD
2023_r1 edition
Application
13086819
A system includes a processor. The processor is configured to receive network traffic that includes a data block. The processor will generate a unique identifier (UID) for the file that includes a hash value corresponding to the file. The processor will determine whether the file is indicated as good or bad with the previously-stored UID. The processor will call a file-type specific detection nugget corresponding to the file's file-type to perform a full file inspection to detect whether the file is good or bad and store a result of the inspection together with the UID of the file, when the file is determined to be not listed in the previously-stored UIDs. The processor will not call the file-type specific detection nugget when the file's indicator is “good” or “bad” in the previously-stored UIDs. The processor will issue an alert about the bad file when the file's indicator is “bad”.
AI classification
Ownership
SOURCEFIRE, INC.
assignment · 261280010
Assignors
OLNEY, MATTHEW, MULLEN, PATRICK, GRENIER, LURENE, HOUGHTON, NIGEL, PENTNEY, RYAN
On an employer assignment, the assignors are typically the inventors.