Patents Assigned to SECURITY MATTERS B.V.
  • Publication number: 20170195197
    Abstract: An intrusion detection method for detecting an intrusion in data traffic on a data communication network parses the data traffic to extract at least one protocol field of a protocol message of the data traffic, and associates the extracted protocol field with a model for that protocol field. The model is selected from a set of models. An assessment is made to determine if a contents of the extracted protocol field is in a safe region as defined by the model, and an intrusion detection signal is generated in case it is established that the contents of the extracted protocol field is outside the safe region. The set of models may comprise a corresponding model for each protocol field of a set of protocol fields.
    Type: Application
    Filed: March 17, 2017
    Publication date: July 6, 2017
    Applicant: Security Matters B.V.
    Inventor: Emmanuele Zambon
  • Patent number: 9628497
    Abstract: An intrusion detection method for detecting an intrusion in data traffic on a data communication network parses the data traffic to extract at least one protocol field of a protocol message of the data traffic, and associates the extracted protocol field with a model for that protocol field. The model is selected from a set of models. An assessment is made to determine if a contents of the extracted protocol field is in a safe region as defined by the model, and an intrusion detection signal is generated in case it is established that the contents of the extracted protocol field is outside the safe region. The set of models may comprise a corresponding model for each protocol field of a set of protocol fields.
    Type: Grant
    Filed: July 26, 2012
    Date of Patent: April 18, 2017
    Assignee: Security Matters B.V.
    Inventor: Emmanuele Zambon
  • Patent number: 9191398
    Abstract: A method and a system for classification of intrusion alerts in computer network is provided. The method comprises the steps of monitoring traffic data in a computer network, detecting an intrusion, providing an intrusion alert and data in relation to the intrusion alert, generating a statistical analysis of the data in relation to the intrusion alert and classifying the intrusion alert based on said statistical analysis. The intrusion alerts and the data in relation to an intrusion alert may be generated by anomaly-based intrusion detection system. The generating a statistical analysis may comprise generating information about a statistical distribution of n-grams in the data. The classification may comprise comparing the statistical analysis with a model analysis of intrusion alerts with predefined alert classes.
    Type: Grant
    Filed: March 31, 2010
    Date of Patent: November 17, 2015
    Assignee: Security Matters B.V.
    Inventors: Damiano Bolzoni, Sandro Etalle
  • Publication number: 20140297572
    Abstract: An intrusion detection method for detecting an intrusion in data traffic on a data communication network parses the data traffic to extract at least one protocol field of a protocol message of the data traffic, and associates the extracted protocol field with a model for that protocol field. The model is selected from a set of models. An assessment is made to determine if a contents of the extracted protocol field is in a safe region as defined by the model, and an intrusion detection signal is generated in case it is established that the contents of the extracted protocol field is outside the safe region. The set of models may comprise a corresponding model for each protocol field of a set of protocol fields.
    Type: Application
    Filed: July 26, 2012
    Publication date: October 2, 2014
    Applicant: Security Matters B.V.
    Inventor: Emmanuele Zambon
  • Publication number: 20120036577
    Abstract: A method and a system for classification of intrusion alerts in computer network is provided. The method comprises the steps of monitoring traffic data in a computer network, detecting an intrusion, providing an intrusion alert and data in relation to the intrusion alert, generating a statistical analysis of the data in relation to the intrusion alert and classifying the intrusion alert based on said statistical analysis. The intrusion alerts and the data in relation to an intrusion alert may be generated by anomaly-based intrusion detection system. The generating a statistical analysis may comprise generating information about a statistical distribution of n-grams in the data. The classification may comprise comparing the statistical analysis with a model analysis of intrusion alerts with predefined alert classes.
    Type: Application
    Filed: March 31, 2010
    Publication date: February 9, 2012
    Applicant: SECURITY MATTERS B.V.
    Inventors: Damiano Bolzoni, Sandro Etalle