首页> 外国专利> Apparatus and method for extracting signature candidates of attacking packets

Apparatus and method for extracting signature candidates of attacking packets

机译:提取攻击分组的签名候选的设备和方法

摘要

An apparatus and method for extracting signature candidates and optimizing a corresponding signature are provided. The apparatus includes a packet separator, a header parser, a traffic information generator, a substring extractor, and a signature candidate extractor. The packet separator separates a packet into a header and a payload. The header information parser parses the header information, and the traffic information generator generates traffic information. The substring extractor measures a frequency of appearing of a substring with a predetermined length in the separated payload for a constant observation period, and extracts a substring having a frequency higher than a predetermined setup value by updating the measured frequency information to a substring frequency table. The signature candidate extractor generates a signature by collecting the extracted substring information and the generated traffic information, updates a signature frequency table, and extracts a signature candidate with reference to information of the signature frequency table.
机译:提供了一种用于提取签名候选并优化相应签名的设备和方法。该设备包括分组分离器,报头解析器,交通信息生成器,子串提取器和签名候选提取器。数据包分隔符将数据包分为标头和有效负载。头信息解析器解析头信息,并且交通信息生成器生成交通信息。子串提取器在恒定的观察周期内测量分离的有效载荷中具有预定长度的子串的出现频率,并且通过将所测量的频率信息更新为子串频率表来提取具有高于预定设置值的频率的子串。签名候选提取器通过收集所提取的子串信息和所生成的交通信息来生成签名,更新签名频率表,并且参考签名频率表的信息来提取签名候选。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号