首页> 外国专利> BLACKLIST MANAGEMENT APPARATUS IN A POLICY-BASED NETWORK SECURITY MANAGEMENT SYSTEM AND ITS PROCEEDING METHOD

BLACKLIST MANAGEMENT APPARATUS IN A POLICY-BASED NETWORK SECURITY MANAGEMENT SYSTEM AND ITS PROCEEDING METHOD

机译:基于策略的网络安全管理系统中的黑名单管理装置及其处理方法

摘要

PURPOSE: A device and a method for managing blacklists in a policy-based network security control system are provided to collect and analyze various network information in real time, so as to notify an operator of user addresses and host addresses exceeding a reference value and generate a network packet cutoff policy for a corresponding IP(Internet Protocol) address. CONSTITUTION: An intrusion detection alarm receiver(301) collects network intrusion alarm data from a security gateway(103) in real time. A dangerous IP address generator(302) extracts blacklist-related information from the collected network intrusion alarm data, and records the extracted information in a potential blacklist DB(307). A blacklist analyzer(303) compares and analyzes whether a network intrusion exceeds a preset threshold from the extracted blacklist-related information. An event generator(304) generates event information to record an event log in a dangerous blacklist DB(309), if the network intrusion is decided to exceed the threshold through the blacklist analyzer(303). A blacklist event monitor(305) notifies the event information generated by the event generator(304) to a remote security manager through a network. And a blacklist cut-off policy manager(310) generates and transmits a packet cutoff policy for a specific IP address through the event information and the event log.
机译:目的:提供一种基于策略的网络安全控制系统中管理黑名单的设备和方法,用于实时收集和分析各种网络信息,以将超出参考值的用户地址和主机地址通知运营商并生成。对应IP(Internet协议)地址的网络数据包切断策略。构成:入侵检测警报接收器(301)实时从安全网关(103)收集网络入侵警报数据。危险IP地址生成器(302)从收集的网络入侵警报数据中提取与黑名单相关的信息,并将提取的信息记录在潜在的黑名单DB(307)中。黑名单分析器(303)从提取的黑名单相关信息中比较并分析网络入侵是否超过预设阈值。如果通过黑名单分析器(303)确定网络入侵超过阈值,则事件产生器(304)产生事件信息以将事件日志记录在危险黑名单DB(309)中。黑名单事件监视器(305)将事件生成器(304)生成的事件信息通过网络通知给远程安全管理器。黑名单截止策略管理器(310)通过事件信息和事件日志生成并发送针对特定IP地址的分组截止策略。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号