首页> 外国专利> Traffic anomaly analysis for the detection of aberrant network code

Traffic anomaly analysis for the detection of aberrant network code

机译:流量异常分析以检测异常网络代码

摘要

A method for detecting nodes in an enterprise network infected with aberrant code is presented in which traffic conversation information representative of traffic conversation in the enterprise network over an analysis period is obtained. Analysis of the obtained traffic conversation information identifies suspected infected nodes in the enterprise network that exhibit behavior outside of the normal behavior associated with the one or more traffic conversation factors. Anomaly analysis may be performed on traffic conversation information associated with the suspected infected nodes to identify any existing infected nodes in the enterprise network.
机译:提出了一种用于检测企业网络中被异常代码感染的节点的方法,其中获得了代表企业网络在分析期内的流量对话的流量对话信息。对获得的交通会话信息的分析可确定企业网络中的可疑受感染节点,这些节点表现出与一个或多个交通会话因素相关的正常行为之外的行为。可以对与可疑感染节点相关联的流量会话信息执行异常分析,以识别企业网络中任何现有的感染节点。

著录项

  • 公开/公告号US2007064617A1

    专利类型

  • 公开/公告日2007-03-22

    原文格式PDF

  • 申请/专利权人 JOSEPH P. REVES;

    申请/专利号US20050227763

  • 发明设计人 JOSEPH P. REVES;

    申请日2005-09-16

  • 分类号G06F12/14;H04J1/16;H04L12/56;G06F11/00;H04L12/26;H04L12/28;

  • 国家 US

  • 入库时间 2022-08-21 21:04:49

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号