首页> 外国专利> System and method for detecting abnormal traffic based on early notification

System and method for detecting abnormal traffic based on early notification

机译:基于早期通知的异常流量检测系统及方法

摘要

This method and system for detecting abnormal traffic in a communications network is based on classifying the traffic in risk and status categories and maintaining a service status table with this information for each service at a respective node. The risk categories are initially established based on known software vulnerabilities recognized for the respective service. An early notifier enables further processing of services suspected of malware propagation. Status categories enable segregating the traffic with a “under attack status” from the “non under attack” status, so that the intrusion detection system at the respective node only processes the “under attack” traffic. In this way, the time and amount of processing performed by the intrusion detection system is considerably reduced.
机译:用于在通信网络中检测异常流量的该方法和系统是基于将流量分类为风险和状态类别,并使用各个节点上每个服务的此信息维护服务状态表。风险类别最初是基于为相应服务识别的已知软件漏洞建立的。早期通知程序可以进一步处理怀疑有恶意软件传播的服务。通过状态类别,可以将处于“处于攻击中”状态的流量与“处于非攻击中”状态隔离开,以便位于相应节点的入侵检测系统仅处理“处于攻击中”的流量。这样,入侵检测系统执行的时间和处理量大大减少了。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号