首页> 外国专利> System and method for reducing false positives during detection of network attacks

System and method for reducing false positives during detection of network attacks

机译:减少网络攻击检测期间误报的系统和方法

摘要

Disclosed are systems and methods for reduction of false positives during detection of network attacks on a protected computer. In one example, the system comprises a proxy device configured to redirect and mirror traffic directed to the protected computer; a traffic sensor configured to collect statistical information about the mirrored traffic; a data collector configured to aggregate information collected by the traffic sensor and to generate traffic filtering rules based on the aggregated statistical information; a filtering center configured to, in parallel with collection of statistical information, filter redirected traffic based on the traffic filtering rules provided by the data collector; and a control module configured to collect and store statistical information about known network attacks and to correct traffic filtering rules used by the filtering center for purpose of reducing false positives during detection of network attacks on the protected computer.
机译:公开了用于在检测到受保护计算机上的网络攻击期间减少误报的系统和方法。在一个示例中,该系统包括代理设备,该代理设备被配置为重定向和镜像定向到受保护计算机的流量。流量传感器,用于收集镜像流量的统计信息;数据收集器,用于收集所述交通传感器收集的信息,并基于所述统计信息生成流量过滤规则;过滤中心,其配置为与统计信息的收集并行,根据数据收集器提供的流量过滤规则过滤重定向流量;控制模块,用于收集和存储有关已知网络攻击的统计信息,并纠正过滤中心使用的流量过滤规则,以减少在受保护计算机上检测到网络攻击期间的误报。

著录项

  • 公开/公告号EP2528005A1

    专利类型

  • 公开/公告日2012-11-28

    原文格式PDF

  • 申请/专利权人 KASPERSKY LAB ZAO;

    申请/专利号EP20120151223

  • 发明设计人 GUDOV NIKOLAY V.;LEVASHOV DMITRY A.;

    申请日2012-01-16

  • 分类号G06F21/00;H04L29/06;

  • 国家 EP

  • 入库时间 2022-08-21 16:32:00

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号