A method for network intrusion detection on a network comprising a plurality of state machines for passing a plurality of network packets comprises determining frequency distributions for each transition within each state machine, determining the distributions of values of each state machine on each transition, and comparing the distributions to observed statistics in the network, and upon determining that the observed statistics are outside defined limits, detecting an anomaly.

 
Web www.patentalert.com

< Signature extraction system and method

> Method and apparatus for verifying the integrity and security of computer networks and implementing counter measures

~ 00430