skip to main content
OSTI.GOV title logo U.S. Department of Energy
Office of Scientific and Technical Information

Title: Intrusion detection using secure signatures

Patent ·
OSTI ID:1159917

A method and device for intrusion detection using secure signatures comprising capturing network data. A search hash value, value employing at least one one-way function, is generated from the captured network data using a first hash function. The presence of a search hash value match in a secure signature table comprising search hash values and an encrypted rule is determined. After determining a search hash value match, a decryption key is generated from the captured network data using a second hash function, a hash function different form the first hash function. One or more of the encrypted rules of the secure signatures table having a hash value equal to the generated search hash value are then decrypted using the generated decryption key. The one or more decrypted secure signature rules are then processed for a match and one or more user notifications are deployed if a match is identified.

Research Organization:
Idaho National Laboratory (INL), Idaho Falls, ID (United States)
Sponsoring Organization:
USDOE
DOE Contract Number:
AC07-05ID14517
Assignee:
U.S. Department of Energy (Washington, DC)
Patent Number(s):
8,850,583
Application Number:
13/785,349
OSTI ID:
1159917
Country of Publication:
United States
Language:
English

References (7)

Efficient signature packing for an intrusion detection system patent November 2009
Detecting public network attacks using signatures and fast content analysis patent-application October 2005
Prioritizing intrusion detection logs patent-application October 2005
Real-time stateful packet inspection method and apparatus patent-application December 2007
Apparatus and Method for High Throughput Network Security Systems patent-application March 2008
Detection of Heavy Users of Network Resources patent-application April 2011
Cloud-Based Gateway Security Scanning patent-application July 2013

Cited By (3)


Similar Records

ECDSA B-233 with Precomputation 1.0 Beta Version
Software · Fri Dec 11 00:00:00 EST 2009 · OSTI ID:1159917

Authentication Protocol for ICS without Encryption
Conference · Mon Jul 01 00:00:00 EDT 2019 · OSTI ID:1159917

Detecting and Blocking Network Attacks at Ultra High Speeds
Technical Report · Mon Nov 29 00:00:00 EST 2010 · OSTI ID:1159917

Related Subjects