首页> 外国专利> Detecting malicious attacks using network behavior and header analysis

Detecting malicious attacks using network behavior and header analysis

机译:使用网络行为和标头分析检测恶意攻击

摘要

A method and apparatus for detecting malicious attacks is described. The method may comprise obtaining routing information from a packet communicated via a network and maintaining a count of packets associated with a device associated with the routing information. For example, the routing information may a source or destination IP address, a port number, or any other routing information. The device may be classified as a potentially malicious device when the count exceeds a threshold. The count may be incremented when the TCP SYN flag is set and the TCP ACK flag is not set. An embodiment comprises obtaining a source hash of the source IP address and a destination hash of the destination IP address. Thereafter, the source hash and the destination hash may be mapped to multi stage filters. The device associated with the packet may then be selectively categorizing as a suspicious device.
机译:描述了一种用于检测恶意攻击的方法和设备。该方法可以包括从经由网络传送的分组中获取路由信息,以及维护与与该路由信息相关联的设备相关联的分组的计数。例如,路由信息可以是源或目标IP地址,端口号或任何其他路由信息。当计数超过阈值时,该设备可能被分类为潜在的恶意设备。当设置了TCP SYN标志并且未设置TCP ACK标志时,该计数可能会增加。一个实施例包括获得源IP地址的源哈希和目的IP地址的目的哈希。此后,可以将源哈希和目标哈希映射到多级过滤器。然后,与分组相关联的设备可以被选择性地归类为可疑设备。

著录项

  • 公开/公告号US7936682B2

    专利类型

  • 公开/公告日2011-05-03

    原文格式PDF

  • 申请/专利权人 SUMEET SINGH;GEORGE VARGHESE;

    申请/专利号US20050271133

  • 发明设计人 GEORGE VARGHESE;SUMEET SINGH;

    申请日2005-11-09

  • 分类号H04L12/26;

  • 国家 US

  • 入库时间 2022-08-21 18:08:24

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号