首页> 外国专利> Automatic detection of malicious packets in DDoS attacks using an encoding scheme

Automatic detection of malicious packets in DDoS attacks using an encoding scheme

机译:使用编码方案自动检测DDOS攻击中的恶意数据包

摘要

A method of detecting patterns in network traffic is provided. The method includes receiving packets of network traffic, performing a frequency analysis per field of the packets as a function of frequency of the occurrence of the same data in the corresponding field, and selecting top values which are values associated with each field of the set of fields that satisfy a criterion as having occurred most frequently in the packets as a function of a result of the frequency analysis. The method further includes assigning a bit encoding scheme that uses variable bit encoding to encode each of the top values for each field that has a top value, encoding into a single value each packet of the packets based on a bitfield representation that uses the encoding scheme for values associated with each field that has a top value, storing each potential combination of fields of the set of fields being processed, with all bits set per field when the field is an active field and no bits set when the field is inactive, performing a bitwise operation on each encoded packet with the stored potential combinations, sorting the results of the bitwise operation based on a number of the active fields and a number of occurrences of each same result of the bitwise operation, and providing the results of the sorting to a mitigation device for determining whether an attack is underway and/or for filtering network traffic for mitigating an attack.
机译:提供了一种检测网络流量中的模式的方法。该方法包括接收网络流量的分组,每个字段执行分组的频率分析,作为相应字段中相同数据的发生频率的函数,以及选择与与集合的每个字段相关联的值的顶部值满足标准的字段,其在数据包中最频繁地发生,作为频率分析结果的函数。该方法还包括分配比特编码方案,该比特编码方案使用可变比特编码来对具有顶部值的每个字段的每个字段对每个字段的每个顶部值基于使用编码方案的位字段表示来对具有顶部值的每个字段编码为分组的每个分组对于与具有顶部值的每个字段相关联的值,存储正在处理的字段集的字段的字段的每个势组合,当字段是活动字段时,当字段是活动字段时,当字段处于非活动状态时,没有设置的位,执行每个编码分组上的按位操作,具有存储的潜在组合,基于多个活动场对位操作的结果分类和相同的比特操作结果的一定数量,并提供排序结果用于确定攻击是否正在进行的缓解设备和/或用于过滤网络流量以减轻攻击。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号