首页> 外国专利> Distributed ISP system for the inspection and elimination of eThreats in a multi-path environment

Distributed ISP system for the inspection and elimination of eThreats in a multi-path environment

机译:用于在多路径环境中检查和消除电子威胁的分布式ISP系统

摘要

Method for eliminating the possibility of exploiting by an attacker a multipath type transfer in terms of the number of the ISP operated Inspection and Elimination Units - IEUs, the method comprises: (a) providing a plurality of Enhanced Inspection and Elimination Units-EIEUs; (b) for each destination subscriber user, defining a set of EIEUs which includes all end EIEUs which can directly forward a packet to said user computer; (c) as long as no conclusion has been reached regarding to whether a session is malicious or not, forwarding all received session packets by any EIEU within the set to a manager EIEU for analysis; (d) upon receipt of a packet at said manager EIEU, forwarding the packet to the destination user computer, but also performing analysis at the manager EIEU on a copy of said packet, together with previously analyzed packets of a same session, in a try to reach a conclusion as to whether the session is malicious or not; (e) if a conclusion has not been reached even following said analysis, accumulating the packet together with said previous packets for further future analysis; (f) if, however, a conclusion is reached by said analysis that the packet belongs to a malicious session, creating a "drop" rule by said manager EIEU, and forwarding to all EIEUs within the set; (g) if, on the other hand, a conclusion is reached by said analysis that the packet belongs to a non-malicious session, creating a "pass" rule by said manager EIEU, and forwarding to all EIEUs within the set.
机译:根据ISP操作的检查和消除单元-IEU的数量消除攻击者利用多径类型转移的可能性的方法,该方法包括:(a)提供多个增强的检查和消除单元-EIEU; (b)对于每个目的地订户用户,定义一组EIEU,其包括可以直接将分组转发到所述用户计算机的所有最终EIEU; (c)只要尚未得出关于会话是否恶意的结论,就将集中的任何EIEU将所有接收到的会话数据包转发给管理者EIEU进行分析; (d)一旦在所述管理器EIEU处接收到分组,就将该分组转发到目的地用户计算机,并且还尝试在所述管理器EIEU上对该分组的副本以及先前分析的同一会话的分组进行分析。得出有关会话是否恶意的结论; (e)如果在进行了上述分析之后仍未得出结论,则将数据包与上述先前的数据包一起累积以进行进一步的未来分析; (f)但是,如果通过上述分析得出的结论是该分组属于恶意会话,则由所述管理者EIEU创建“丢弃”规则,并转发到该组内的所有EIEU; (g)另一方面,如果通过所述分析得出的结论是该分组属于非恶意会话,则由所述管理者EIEU创建“通过”规则,并转发到该组内的所有EIEU。

著录项

  • 公开/公告号EP2040437B1

    专利类型

  • 公开/公告日2015-05-06

    原文格式PDF

  • 申请/专利权人 DEUTSCHE TELEKOM AG;

    申请/专利号EP20080016740

  • 发明设计人 CHAI ELDAD;FELSTAINE EYAL;GILBOA NIV;

    申请日2008-09-24

  • 分类号H04L29/06;

  • 国家 EP

  • 入库时间 2022-08-21 15:08:47

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号