首页> 外国专利> Attack detection system, attack detection equipment, attack detection methods and attack detection program

Attack detection system, attack detection equipment, attack detection methods and attack detection program

机译:攻击检测系统,攻击检测设备,攻击检测方法和攻击检测程序

摘要

[Problems] The long-term log analysis as well as carried out in real time, it determines the continuity of attack for efficient security operations by preventing duplicate detection of events. A attack detection unit 10 uses the collected logs, every predetermined short time period, and counts the number of times the communication destination IP address of the user terminal matches the destination IP address of the blacklist. Also, the attack detection unit 10, using the number of times that is counted in a predetermined period among the counted number of times per a predetermined long time to detect the unauthorized communication conforming to the predetermined detection rule of the communication user terminal . Then, the attack detecting device 10, among the sensed unauthorized communications, it is determined whether the communication source IP address and destination IP address as the illegal communication is detected within a predetermined time period there is a bad communication are the same, is the same If there is bad communication, detects that said non positive communication is continuing state. .BACKGROUND 2
机译:[问题]长期日志分析以及实时进行,它通过防止重复检测事件来确定攻击连续性,以进行有效的安全操作。攻击检测单元10每隔预定的短时间使用收集的日志,并对用户终端的通信目标IP地址与黑名单的目标IP地址匹配的次数进行计数。而且,攻击检测单元10使用在每预定长时间内所计数的次数中在预定时间段内所计数的次数,来检测符合通信用户终端的预定检测规则的未授权通信。然后,攻击检测设备10,在检测到的未经授权的通信中,确定在预定时间段内是否检测到非法通信的通信源IP地址和目的IP地址是否存在不良通信,是否相同。如果存在不良通信,则检测到所述非肯定通信处于继续状态。 。背景2

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号