首页> 外国专利> FEATURE QUANTITY EXTRACTING METHOD FOR DETECTING ABNORMALITY OF NETWORK, PROGRAM FOR ALLOWING COMPUTER TO EXECUTE THE METHOD, FEATURE QUANTITY EXTRACTING APPARATUS, AND NETWORK ABNORMALITY DETECTING SYSTEM

FEATURE QUANTITY EXTRACTING METHOD FOR DETECTING ABNORMALITY OF NETWORK, PROGRAM FOR ALLOWING COMPUTER TO EXECUTE THE METHOD, FEATURE QUANTITY EXTRACTING APPARATUS, AND NETWORK ABNORMALITY DETECTING SYSTEM

机译:用于检测网络异常的特征量提取方法,允许计算机执行该方法的程序,用于特征量提取的装置以及网络异常检测系统

摘要

PROBLEM TO BE SOLVED: To provide a feature quantity extracting method for detecting abnormality of a network or the like enhancing detection accuracy of an illegitimate access such as an attack by using an abnormality detection system.;SOLUTION: The method segments an observation slot by a feature quantity extracting section 13a on the basis of an event including traffic such as a SYN packet as a feature quantity capturing a quantitative change in the traffic delivered from the Internet 11 to a network of a LAN 12 to extract the feature quantity. A data generating section 13b generates a distribution pattern of the traffic on the basis of the feature quantity, and the feature quantity extracting apparatus compares a distribution pattern in an ordinary state of the network with a distribution pattern in operation to detect the abnormality state of the network.;COPYRIGHT: (C)2005,JPO&NCIPI
机译:解决的问题:提供一种特征量提取方法,用于检测网络等的异常,从而通过使用异常检测系统来提高诸如攻击之类的非法访问的检测精度。特征量提取部分13a基于包括诸如SYN分组之类的业务的事件作为特征量,以捕获从因特网11传送到LAN 12的网络的业务量的定量变化以提取特征量。数据生成部13b根据特征量来生成业务量的分布模式,特征量提取装置将网络的通常状态下的分布模式与运行中的分布模式进行比较,以检测网络的异常状态。网络;版权所有:(C)2005,JPO&NCIPI

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号