首页> 外国专利> Attack detecting device, attack detection system and attack detection method

Attack detecting device, attack detection system and attack detection method

机译:攻击检测装置,攻击检测系统及攻击检测方法

摘要

PROBLEM TO BE SOLVED: To allow for appropriate detection of network attack, detection of which is difficult by simple comparison of the packet count of flow with a threshold.SOLUTION: A server device 3 has a packet count information acquisition unit 311 for acquiring, from a transfer device having a packet count function, packet count information associating the count of packets of a monitoring object flow passed through the transfer device with each passing time of the packet of a counted monitoring object flow, a burst duration measurement unit 332 for measuring a burst duration where such a burst state as the packet interval of the monitoring object flow is less than a certain time interval continues, based on the packet count information, and an aggression detector 333 for detecting attack to the monitoring object flow, based on the comparison result the burst duration of the monitoring object flow measured by the burst duration measurement unit 332 and a predetermined threshold.SELECTED DRAWING: Figure 4
机译:解决的问题:为了允许适当地检测网络攻击,通过简单比较流的分组计数与阈值来检测网络攻击是困难的。解决方案:服务器设备3具有分组计数信息获取单元311,用于从中获取具有分组计数功能的传输设备,将通过该传输设备的监视对象流的分组计数与所计数的监视对象流的分组的每个通过时间相关联的分组计数信息,突发持续时间测量单元332,用于测量根据该分组计数信息,持续进行突发持续时间,其中,突发状态(诸如监视对象流的分组间隔小于某个时间间隔)持续,并且基于比较,攻击检测器333用于检测对监视对象流的攻击结果由突发持续时间测量单元332测量的监视对象流的突发持续时间和预定阈值。演讲稿:图4

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号