Inventors:
Ramasubramanian Sekar - East Setauket NY, US
Assignee:
Research Foundation of the State University of New York - Stony Brook NY
International Classification:
G06F 11/00
US Classification:
726 23, 726 22, 726 26, 713188, 709224
Abstract:
A method for network intrusion detection on a network comprising a plurality of state machines for passing a plurality of network packets comprises determining frequency distributions for each transition within each state machine, determining the distributions of values of each state machine on each transition, and comparing the distributions to observed statistics in the network, and upon determining that the observed statistics are outside defined limits, detecting an anomaly.