首页> 外国专利> A SYSTEM AND METHOD FOR NETWORK INTRUSION DETECTION OF COVERT CHANNELS BASED ON OFF-LINE NETWORK TRAFFIC

A SYSTEM AND METHOD FOR NETWORK INTRUSION DETECTION OF COVERT CHANNELS BASED ON OFF-LINE NETWORK TRAFFIC

机译:基于离线网络流量的秘密渠道网络入侵检测系统及方法

摘要

A network intrusion detection system and method is configured to receive off-line network traffic. The off-line network traffic with a predefined format, PCAP file, is capable of indicating existence of a plurality of covert channels associated with a corresponding plurality of covert channel signatures. Each covert channel comprises a tool that communicates messages by deviating from a standard protocol to avoid detection. A plurality of covert channel processors are configured to analyze off-line network traffic. The analysis determines whether the off-line network traffic deviates from the standard protocol based on one or more covert channel signatures. The covert channels are employed in at least one standard layer of the standard protocol stack and the off-line network data traffic comprises at least one standard protocol stack having multiple standard layers.
机译:网络入侵检测系统和方法被配置为接收离线网络流量。具有预定格式PCAP文件的离线网络业务能够指示与对应的多个隐蔽信道签名相关联的多个隐蔽信道的存在。每个隐蔽通道都包含一个工具,该工具通过偏离标准协议来避免检测,从而传达消息。多个隐蔽信道处理器被配置为分析离线网络流量。该分析基于一个或多个隐蔽通道签名确定离线网络流量是否偏离标准协议。隐蔽信道被用在标准协议栈的至少一个标准层中,并且离线网络数据业务包括具有多个标准层的至少一个标准协议栈。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号