首页> 外国专利> METHOD FOR THE TREE STRUCTURE REPRESENTATION OF A GROUP OF DIGITAL DATA STREAMS, THE ASSOCIATED TREE STRUCTURE AND METHOD AND SYSTEM FOR THE DETECTION OF A FLOOD ATTACK

METHOD FOR THE TREE STRUCTURE REPRESENTATION OF A GROUP OF DIGITAL DATA STREAMS, THE ASSOCIATED TREE STRUCTURE AND METHOD AND SYSTEM FOR THE DETECTION OF A FLOOD ATTACK

机译:一组数字数据流的树结构表示方法,相关的树结构以及洪水攻击的检测方法和系统

摘要

The invention relates to a method of using an adaptive tree structure in order to represent a group of digital data streams (AFL[AJ,VL]), which is formed by at least one candidate stream (CFk[AkVk]). The inventive method consists in passing through (A) each node (NL[A,A',L',A',L',V]) of a tree structure having an address that corresponds to all or part of a common address part of the destination address (Ak) of a candidate stream or a group of streams; creating at least one leaf for each destination address part of a candidate stream that is different from said common address part (B), each node or leaf having an associated state variable (V), (Vk) that is representative of the candidate stream or a group of streams in terms of network occupancy; assigning each node (NL[A,A',L',A',L',V]) or leaf passed through or created (C), (D) an average behaviour variable (MB(MVNSVN)) in terms of network occupancy as a function of the state variable; controlling (C), (D), at least the creation of a node or a leaf and the updating of the average behaviour variable based on a criterion for discrimination of the common address part or the address of the group of streams or of the candidate stream in relation to the nodes and leaves; and comparing the behaviour of the node with the normal behaviour which depends on the number of leaves N that are associated with said node. The invention can be used for the technical management of IP networks, corporate networks and other networks and for the detection of a flood attack.
机译:本发明涉及一种使用自适应树结构来表示一组数字数据流(AFL [AJ,VL])的方法,该组数字数据流由至少一个候选流(CFk [AkVk])形成。本发明的方法在于使具有对应于全部或部分公共地址部分的地址的树形结构的(A)每个节点(NL [A,A',L',A',L',V])通过。候选流或一组流的目的地址(Ak);为与所述公共地址部分(B)不同的候选流的每个目的地址部分创建至少一个叶子,每个节点或叶子具有代表候选流的相关状态变量(V),(Vk)或就网络占用而言,一组流;为每个节点(NL [A,A',L',A',L',V])或经过或创建的叶子分配(C),(D)网络平均行为变量(MB(MVNSVN))占用率是状态变量的函数;基于判别公共地址部分或流组或候选地址的标准,至少控制(C),(D),节点或叶的创建以及平均行为变量的更新关于节点和叶子的流;将节点的行为与正常行为进行比较,该行为取决于与所述节点相关联的叶子N的数量。本发明可以用于IP网络,公司网络和其他网络的技术管理以及用于泛洪攻击的检测。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号