首页> 外国专利> Regulatory Network Threat Detection

Regulatory Network Threat Detection

机译:监管网络威胁检测

摘要

A package filter device, comprising:at least one processor; anda memory comprising instructions that, when executed by at least one processor, induce the packet filter device to:receive a variety of package filter rules that are configured to cause the package filter device to identify packages that correspond to at least one of a variety of network threat indicators, with the variety of network threat indicators associated with network threat intelligence reports, provided by one or more independent network threat intelligence providers;receive a large number of packages comprising a first and a second package;in response to a provision that the first package complies with a first package filter rule of a multitude of package filter rules based on one or more network threat indicators of the multitude of network threat indicators defined by the first package filter rule:apply an operator to the first package defined by the first packet filter rule and configured to cause the packet filter device to allow the first package to be redirected towards a destination of the first package; andto transmit information identifying one or more network threat indicators and data indicating that the first package has been allowed to be forwarded towards the target of the first package;receive an update of at least one package filter rule;modify, based on the received update of at least one packet filter rule, at least one operator defined by the first packet filter rule to reconfigure the packet filter device so that packets corresponding to one or more network threat indicators, be prevented from moving towards their respective objectives; andin response to a provision that the second package complies with the first packet filter rule:on the basis of the modified at least one operator defined by the first packet filter rule to prevent the second packet from being diverted towards a second packet target; andTransmit data indicating that the second package has been obstructed in the forwarding towards the target of the second package.
机译:包装滤波器设备,包括:至少一个处理器;和包括指令的内存,当由至少一个处理器执行时,将分组滤波器设备引起:接收各种包过滤规则,该规则被配置为使包过滤器设备识别对应于各种网络威胁指标中的至少一个的包,其中包含与网络威胁情报报告相关的各种网络威胁指示符或者更多的独立网络威胁情报提供者;接收包含第一和第二包装的大量包装;响应于第一个包符合第一个包过滤规则的第一个包过滤规则,基于第一个包过滤规则定义的众多网络威胁指示符的一个或多个网络威胁指示符:将运算符应用于由第一分组滤波器规则定义的第一个包,并被配置为使分组过滤器设备允许将第一包重定向到第一包的目的地;和要传输识别一个或多个网络威胁指示符和数据的信息,指示已经允许向第一包的目标转发第一包的数据;收到至少一个包过滤规则的更新;基于至少一个分组滤波器规则的接收更新,至少一个由第一分组滤波器规则定义的操作员来重新配置分组滤波器设备,以便阻止与一个或多个网络威胁指示符相对应的分组移动各自的目标;和响应于第二个包符合第一个数据包过滤规则的规定:基于由第一分组滤波器规则定义的修改的至少一个操作员,以防止第二分组转移朝向第二分组目标;和发送数据,指示第二包在转发中被朝向第二封装的目标被屏蔽。

著录项

  • 公开/公告号DE202016009026U1

    专利类型

  • 公开/公告日2021-08-26

    原文格式PDF

  • 申请/专利权人 CENTRIPETAL NETWORKS INC.;

    申请/专利号DE20162009026U

  • 发明设计人

    申请日2016-04-07

  • 分类号H04L12/26;

  • 国家 DE

  • 入库时间 2022-08-24 20:49:02

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号