Abstract: An active monitor detects and classifies messages transmitted on a network. In one form, the monitor includes a routine for classifying TCP packet source addresses as being of an acceptable, unacceptable, or suspect type. Suspect source addresses may be further processed in accordance with a state machine having a number of conditionally linked states including a good address state, a new address state, and a bad address state.
Type:
Grant
Filed:
April 15, 1999
Date of Patent:
April 20, 2004
Assignee:
Purdue Research Foundation
Inventors:
Christoph L. Schuba, Ivan V. Krsul, Diego Zamboni, Eugene H. Spafford, Aurobindo M. Sundaram, Markus G. Kuhn