首页> 外国专利> Fast identification of offense and attack execution in network traffic patterns

Fast identification of offense and attack execution in network traffic patterns

机译:在网络流量模式中快速识别进攻和攻击执行

摘要

A method, apparatus and computer system to identify threats on a TCP/IP-based network. The approach leverages a set of reference patterns (or “network spectrals”) associated with one or more defined Indicators of Compromise (IoCs). At least one reference pattern is time-bounded and profiles a network traffic pattern using a set of session data (e.g., volume, direction, traffic metadata) that is payload-neutral and may be derived in part by time-series compression of at least one non-varying encoding interval. Network traffic data associated with a traffic pattern under test is received and encoded to generate a test spectral. A stream-based real-time comparison is performed to determine whether the test spectral matches against any of the reference spectrals. Responsive to identifying a match, a given remediation or mitigation action is then taken. A reference spectral may represent a bi- or multi-directional flow, and the multi-directional flow may involve multiple entities.
机译:一种方法,装置和计算机系统,用于识别基于TCP / IP网络的威胁。 该方法利用与一个或多个折衷指示符相关联的一组参考模式(或“网络频谱”),与折衷指示器(IOC)相关联。 至少一个参考模式是时间限定的,并且使用作为有效载荷 - 中性的一组会话数据(例如,卷,方向,业务元数据)来配置网络流量模式,并且可以至少通过时间串联压缩来导出 一个非变化的编码间隔。 接收和编码与正在测试的流量模式相关联的网络流量数据以生成测试频谱。 执行基于流的实时比较以确定测试频谱是否与任何参考光谱匹配。 响应识别匹配,然后采取给定的修复或缓解作用。 参考光谱可以表示双向或多方向性,并且多向流可以涉及多个实体。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号