首页> 外国专利> Efficient packet capture for cyber threat analysis

Efficient packet capture for cyber threat analysis

机译:高效的数据包捕获,可进行网络威胁分析

摘要

Methods, systems, and computer-readable media for efficiently detecting threat incidents for cyber threat analysis are described herein. In various embodiments, a computing device, which may be located at a boundary between a protected network associated with the enterprise and an unprotected network, may combine one or more threat indicators received from one or more threat intelligence providers; may generate one or more packet capture and packet filtering rules based on the combined threat indicators; and, may capture or filter, on a packet-by-packet basis, at least one packet based on the generated rules. In other embodiments, a computing device may generate a packet capture file comprising raw packet content and corresponding threat context information, wherein the threat context information may comprise a filtering rule and an associated threat indicator that caused the packet to be captured.
机译:本文描述了用于有效地检测威胁事件以进行网络威胁分析的方法,系统和计算机可读介质。在各种实施例中,可以位于与企业相关联的受保护网络与不受保护的网络之间的边界处的计算设备可以组合从一个或多个威胁情报提供者接收到的一个或多个威胁指示符。可以基于组合的威胁指示符来生成一个或多个分组捕获和分组过滤规则;并且,可以基于生成的规则在逐个分组的基础上捕获或过滤至少一个分组。在其他实施例中,计算设备可以生成包括原始分组内容和对应的威胁上下文信息的分组捕获文件,其中威胁上下文信息可以包括导致​​捕获分组的过滤规则和相关联的威胁指示符。

著录项

  • 公开/公告号AU2016384755A1

    专利类型

  • 公开/公告日2018-08-16

    原文格式PDF

  • 申请/专利权人 CENTRIPETAL NETWORKS INC.;

    申请/专利号AU20160384755

  • 发明设计人 AHN DAVID K.;MOORE SEAN;

    申请日2016-12-21

  • 分类号H04L29/06;

  • 国家 AU

  • 入库时间 2022-08-21 12:45:23

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号