首页> 外国专利> System and method for reducing false positives during detection of network attacks

System and method for reducing false positives during detection of network attacks

机译:减少网络攻击检测期间误报的系统和方法

摘要

Disclosed are systems, methods and computer program products for reduction of false positives during detection of network attacks on a protected computer. In one example, the system comprises a proxy device configured to redirect and mirror traffic directed to the protected computer; a traffic sensor configured to collect statistical information about the mirrored traffic; a data collector configured to aggregate information collected by the traffic sensor and to generate traffic filtering rules based on the aggregated statistical information; a filtering center configured to, in parallel with collection of statistical information, filter redirected traffic based on the traffic filtering rules provided by the data collector; and a control module configured to collect and store statistical information about known network attacks and to correct traffic filtering rules used by the filtering center for purpose of reducing false positives during detection of network attacks on the protected computer.
机译:公开了用于在检测到受保护计算机上的网络攻击期间减少误报的系统,方法和计算机程序产品。在一个示例中,该系统包括代理设备,该代理设备被配置为重定向和镜像定向到受保护计算机的流量;流量传感器,用于收集镜像流量的统计信息;数据收集器,用于对所述交通传感器收集到的信息进行汇总,并基于汇总的统计信息生成流量过滤规则;过滤中心,用于与统计信息的收集并行,根据数据收集器提供的流量过滤规则,过滤重定向流量;控制模块,被配置为收集和存储有关已知网络攻击的统计信息,并纠正过滤中心使用的流量过滤规则,以减少在检测到受保护计算机上的网络攻击期间的误报。

著录项

  • 公开/公告号EP2528005B1

    专利类型

  • 公开/公告日2015-06-17

    原文格式PDF

  • 申请/专利权人 KASPERSKY LAB ZAO;

    申请/专利号EP20120151223

  • 发明设计人 GUDOV NIKOLAY V.;LEVASHOV DMITRY A.;

    申请日2012-01-16

  • 分类号G06F21/00;H04L29/06;

  • 国家 EP

  • 入库时间 2022-08-21 15:07:17

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号