首页> 外国专利> CLUSTER-BASED DETERMINATION OF SIGNATURES FOR DETECTION OF ANOMALOUS DATA TRAFFIC

CLUSTER-BASED DETERMINATION OF SIGNATURES FOR DETECTION OF ANOMALOUS DATA TRAFFIC

机译:基于聚类的异常数据流量检测信号确定

摘要

Provided are methods and systems for cluster-based determination of signatures for detection of anomalous data traffic. An example method may include capturing, by a network module, data packets routed to a destination. The method may further include grouping, by at least one processor in communication with the network module, the data packets into clusters. The method may also include detecting, by the processor, an anomaly in the data packets and, in response to the detection, determining, by the processor and based on the clusters, one or more signatures associated with the data packets. The method may further include generating, by the processor and based on the signatures, one or more rules for allowing the data packets. The method may further include providing, by the processor, the one or more rules to a policy enforcement point associated with the destination.
机译:提供了用于基于簇的签名确定以检测异常数据流量的方法和系统。示例方法可以包括由网络模块捕获路由到目的地的数据分组。该方法可以进一步包括通过与网络模块通信的至少一个处理器将数据分组分组为集群。该方法还可以包括:由处理器检测数据分组中的异常,并且响应于该检测,由处理器基于集群并且确定与数据分组相关联的一个或多个签名。该方法可以进一步包括由处理器并基于签名生成用于允许数据分组的一个或多个规则。该方法可以进一步包括由处理器将一个或多个规则提供给与目的地相关联的策略实施点。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号