首页> 外国专利> Automatically detecting malicious computer network reconnaissance by updating state codes in a histogram

Automatically detecting malicious computer network reconnaissance by updating state codes in a histogram

机译:通过更新直方图中的状态码来自动检测恶意计算机网络侦察

摘要

A detection and response system that generates an Alert if unauthorized scanning is detected on a computer network that includes a look-up table to record state value corresponding to the sequence in which SYN, SYN/ACK and RST packets are observed. A set of algorithms executed on a processing engine adjusts the state value in response to observing the packets. When the state value reaches a predetermined value indicating that all three packets have been seen, the algorithm generates an Alert.
机译:如果在计算机网络上检测到未经授权的扫描,则该检测和响应系统将生成警报,该系统包括一个查找表,用于记录与观察到SYN,SYN / ACK和RST数据包的顺序相对应的状态值。在处理引擎上执行的一组算法会响应于观察到数据包来调整状态值。当状态值达到指示已看到所有三个数据包的预定值时,该算法将生成警报。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号