首页>
外国专利>
Fast identification of offense and attack execution in network traffic patterns
Fast identification of offense and attack execution in network traffic patterns
展开▼
机译:在网络流量模式中快速识别进攻和攻击执行
展开▼
页面导航
摘要
著录项
相似文献
摘要
A method, apparatus and computer system to identify threats on a TCP/IP-based network. The approach leverages a set of reference patterns (or “network spectrals”) associated with one or more defined Indicators of Compromise (IoCs). At least one reference pattern is time-bounded and profiles a network traffic pattern using a set of session data (e.g., volume, direction, traffic metadata) that is payload-neutral and may be derived in part by time-series compression of at least one non-varying encoding interval. Network traffic data associated with a traffic pattern under test is received and encoded to generate a test spectral. A stream-based real-time comparison is performed to determine whether the test spectral matches against any of the reference spectrals. Responsive to identifying a match, a given remediation or mitigation action is then taken. A reference spectral may represent a bi- or multi-directional flow, and the multi-directional flow may involve multiple entities.
展开▼