首页> 外国专利> THE PACKET-BASED THREATS DETECTION METHOD OF PROVIDING ENCRYPT TRAFFIC VISIBLITY

THE PACKET-BASED THREATS DETECTION METHOD OF PROVIDING ENCRYPT TRAFFIC VISIBLITY

机译:基于数据包的威胁检测方法提供加密的流量可见性

摘要

The present invention relates to a packet-based threat detection method that provides encryption traffic visibility. In the method of the present invention, the intrusion detection engine of the packet-based threat detection device detects a threat and blocks the detected traffic data, and the YARA detection engine re-detects the traffic data for which no threat is detected by the intrusion detection engine. Including, the YARA rule of the YARA detection engine is uploaded to the internal logic of the FPGA (Field Programmable Gate Array) to match the header value of the packets passing through the FPGA and all the data in the payload in real time. It is characterized by including.
机译:本发明涉及一种基于分组的威胁检测方法,其提供加密业务可见性。在本发明的方法中,基于分组的威胁检测设备的入侵检测引擎检测威胁并阻止检测到的业务数据,并且yara检测引擎重新检测到侵入中没有检测到威胁的业务数据检测引擎。包括,yara检测引擎的yara规则被上传到FPGA(现场可编程门阵列)的内部逻辑,以匹配通过FPGA的数据包的标题值以及实时有效载荷中的所有数据。它的特征在于包括。

著录项

  • 公开/公告号KR102239762B1

    专利类型

  • 公开/公告日2021-04-13

    原文格式PDF

  • 申请/专利权人

    申请/专利号KR1020190106483

  • 发明设计人 이호재;강병완;박석영;

    申请日2019-08-29

  • 分类号H04L29/06;G06F9/30;H04L29/08;

  • 国家 KR

  • 入库时间 2022-08-24 18:11:38

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号