首页> 外国专利> BLACK LIST SETTING APPARATUS, BLACK LIST SETTING METHOD, AND BLACK LIST SETTING PROGRAM

BLACK LIST SETTING APPARATUS, BLACK LIST SETTING METHOD, AND BLACK LIST SETTING PROGRAM

机译:黑名单设置装置,黑名单设置方法和黑名单设置程序

摘要

To generate a black list with reduced number of rules without significantly lowering the detection rate when the number of rules that can be set for a device is limited.SOLUTION: An acquisition unit 141 acquires the attack type and the number of attacks for each IP address of the attack source with respect to a cyber attack observed on the Internet. Further, a calculation unit 142 calculates a parameter of a distribution function when the distribution of the number of attacks for each of the IP addresses of the attack source is represented by a predetermined distribution function for each of the attack types. In addition, under a constraint condition in which the number of selectable IP addresses is equal to or less than a predetermined upper limit value, a selection unit 143 selects the IP address to be set in a black list from the IP address of the attack source such that the detection rate for the cyber attack predicted on the basis of the distribution function and the distribution parameter is maximized.SELECTED DRAWING: Figure 1
机译:当可以为设备设置的规则数量受到限制时,要生成规则数量减少的黑名单,而又不会显着降低检测率。解决方案:获取单元141获取每个IP地址的攻击类型和攻击数量与在Internet上观察到的网络攻击有关的攻击源。此外,当针对攻击源的每个IP地址的攻击数量的分布由针对每种攻击类型的预定分布函数表示时,计算单元142计算分布函数的参数。另外,选择单元143在可选IP地址的数量等于或小于预定上限值的约束条件下,从攻击源的IP地址中选择要在黑名单中设置的IP地址。这样就可以最大程度地提高根据分布函数和分布参数预测的网络攻击的检测率。图1

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号