首页> 外国专利> ATTACK TRAFFIC DETECTING METHOD AND ATTACK TRAFFIC DETECTING DEVICE

ATTACK TRAFFIC DETECTING METHOD AND ATTACK TRAFFIC DETECTING DEVICE

机译:攻击流量检测方法及攻击流量检测装置

摘要

PPROBLEM TO BE SOLVED: To reduce false detection and oversight of an attack packet by monitoring attacks at different monitoring intervals and setting a threshold of each different monitoring interval according to attack success or failure probability. PSOLUTION: In the attack traffic detecting method, a plurality of monitoring intervals are held and the monitoring intervals are defined as TSB1/SB, TSB2/SB, ..., TSBn/SBin the ascending order. When the attack success or failure probability is given to the number R of attack packet rates and an attack duration T using F(R, T), rSBi/SBthat satisfies F(rSBi/SB, TSBi+1/SBaSBi/SB)eSBi/SBis set in predetermined parameters aSBi/SBand eSBi/SBas a threshold rSBi/SBwith respect to the monitoring interval TSBi/SB. The acquired number of packets is divided by the monitoring interval TSBi/SBto calculate the number Ri of rates. When the number RSBi/SBof rates in the monitoring interval exceeds the threshold rSBi/SB, it is detected as attack traffic in any one of the plurality of monitoring intervals. PCOPYRIGHT: (C)2010,JPO&INPIT
机译:

要解决的问题:通过以不同的监视间隔监视攻击并根据攻击成功或失败的概率设置每个不同监视间隔的阈值,以减少对攻击包的错误检测和监督。

解决方案:在攻击流量检测方法中,保留多个监视间隔,并将监视间隔定义为T 1 ,T 2 ,..., T n 升序。当使用F(R,T)将攻击成功率或失败概率分配给攻击数据包速率的数量R和攻击持续时间T时,满足F(r i i 在预定参数a i 和e中设置SB>,T i + 1 a i i i 作为监视间隔T i 的阈值r i 。将获取的数据包数量除以监视间隔T i ,以计算速率的数量Ri。当监视间隔中的速率数R i 超过阈值r i 时,将其检测为多个监视间隔中任意一个的攻击流量。

版权:(C)2010,日本特许厅&INPIT

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号