首页> 外国专利> METHOD FOR REAL-TIME ENCRYPTION PACKET SEPARATION AND IDENTIFICATION IN HIGH SPEED TRAFFIC AND INTERWORKING WITH YARA DETECTION ON IDENTIFIED PACKET AND APPARATUS THEREOF

METHOD FOR REAL-TIME ENCRYPTION PACKET SEPARATION AND IDENTIFICATION IN HIGH SPEED TRAFFIC AND INTERWORKING WITH YARA DETECTION ON IDENTIFIED PACKET AND APPARATUS THEREOF

机译:高速交通中实时加密包的分离与识别方法以及与识别包的yara检测交互的方法及其装置

摘要

The present invention relates to a packet-based threat detection device that provides visibility of encrypted traffic in conjunction with YARA detection technology. The device of the present invention is implemented based on a hardware module including a Field Programmable Gate Array (FPGA) and memory. In addition, the packet-based threat detection apparatus of the present invention detects a threat by applying an encryption traffic decryption engine 110 that decrypts encrypted network traffic data using a certificate, and a predetermined intrusion detection rule on the decrypted traffic data. With respect to the blocking intrusion detection engine 120 and the traffic data for which no threat is detected by the intrusion detection engine 110, the traffic data is not combined to generate a complete file, but a YARA rule is applied on a packet basis. Includes a packet-based YARA detection engine (130) that redetects threats.
机译:基于分组的威胁检测设备技术领域本发明涉及一种基于分组的威胁检测设备,其结合YARA检测技术提供了加密流量的可见性。本发明的设备基于包括现场可编程门阵列(FPGA)和存储器的硬件​​模块来实现。另外,本发明的基于分组的威胁检测设备通过应用加密业务解密引擎110来检测威胁,该加密业务解密引擎110使用证书以及对解密的业务数据的预定入侵检测规则来对加密的网络业务数据进行解密。关于阻塞入侵检测引擎120和入侵检测引擎110未检测到威胁的交通数据,不对交通数据进行组合以生成完整文件,而是基于分组应用YARA规则。包括重新检测威胁的基于分组的YARA检测引擎(130)。

著录项

  • 公开/公告号KR102152313B1

    专利类型

  • 公开/公告日2020-09-04

    原文格式PDF

  • 申请/专利权人 (주)피즐리소프트;

    申请/专利号KR20190106481

  • 发明设计人 이호재;강병완;박석영;

    申请日2019-08-29

  • 分类号H04L29/06;G06F9/30;H04L29/08;

  • 国家 KR

  • 入库时间 2022-08-21 11:03:53

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号