首页> 外国专利> METHODS AND SYSTEMS FOR AUTOMATED DETECTION AND TRACKING OF NETWORK ATTACKS

METHODS AND SYSTEMS FOR AUTOMATED DETECTION AND TRACKING OF NETWORK ATTACKS

机译:自动检测和跟踪网络攻击的方法和系统

摘要

Methods for tracking attacking nodes are described and include extracting, from a database, an instance of each unique packet header associated with IP-to-IP packets transmitted over a time period. The method includes determining from extracted headers, which nodes have attempted to establish a connection with an excessive number of other nodes over a period, identifying these as potential attacking nodes, determining from the headers, which other nodes responded with a TCP SYN/ACK packet indicating a willingness to establish connections, and a potential for compromise. Nodes scanned by potential attacking nodes are disqualified from the identified nodes based on at least one of: data in the headers relating to at least one of an amount of data transferred, and scanning activities conducted by the nodes that responded to a potential attacking node with a TCP SYN/ACK packet. Any remaining potential attacking nodes and scanned nodes are presented to a user.
机译:描述了跟踪攻击节点的方法,该方法包括从数据库中提取与在一段时间内传输的IP到IP数据包相关的每个唯一数据包头的实例。该方法包括:从提取的报头中确定在一段时间内哪些节点已尝试与数量过多的其他节点建立连接;将这些节点标识为潜在攻击节点;从报头中确定哪些其他节点以TCP SYN / ACK数据包进行了响应表示愿意建立联系以及潜在的折衷办法。潜在攻击节点扫描的节点根据以下至少一项与已标识的节点不匹配:头中的数据与所传输的大量数据中的至少一项有关,以及由响应潜在攻击节点的节点执行的扫描活动TCP SYN / ACK数据包。任何剩余的潜在攻击节点和扫描节点都呈现给用户。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号