首页> 外国专利> METHOD AND APPARATUS FOR GENERATING NETWORK INTRUSION DETECTION RULE

METHOD AND APPARATUS FOR GENERATING NETWORK INTRUSION DETECTION RULE

机译:生成网络入侵检测规则的方法和装置

摘要

The present invention relates to a method that, in order to automatically generate an intrusion detection rule used in a network intrusion detection system, when a set of existing intrusion detection rules, normal network traffic, suspicious network traffic, and a maximum intrusion detection rule length are given as inputs, filters out strings that are not included in the normal network traffic but are included only in the suspicious network traffic, calculates similarities between the filtered strings and the existing intrusion detection rules, and then selects the most similar intrusion detection rule to a new attack, thereby providing an intrusion detection rule candidate for the new attack by using the most similar intrusion detection rule.
机译:本发明涉及一种方法,当一组现有入侵检测规则,正常网络流量,可疑网络流量和最大入侵检测规则长度时,为了自动生成在网络入侵检测系统中使用的入侵检测规则。用作输入,过滤掉不包含在正常网络流量中但仅包含在可疑网络流量中的字符串,计算过滤后的字符串与现有入侵检测规则之间的相似度,然后选择最相似的入侵检测规则来新攻击,从而通过使用最相似的入侵检测规则为新攻击提供入侵检测规则候选。

著录项

  • 公开/公告号WO2018110997A1

    专利类型

  • 公开/公告日2018-06-21

    原文格式PDF

  • 申请/专利权人 INFNIS NETWORKS INC.;

    申请/专利号WO2017KR14716

  • 发明设计人 PARK DONG KI;

    申请日2017-12-14

  • 分类号H04L29/06;

  • 国家 WO

  • 入库时间 2022-08-21 12:43:41

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号