会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 8. 发明申请
    • DETECTING ANOMALY ACTION WITHIN A COMPUTER NETWORK
    • 检测计算机网络中的异常行为
    • US20160234167A1
    • 2016-08-11
    • US15075343
    • 2016-03-21
    • LIGHT CYBER LTD.
    • Giora EngelMichael Mumcuoglu
    • H04L29/06H04L12/26
    • H04L63/1408H04L43/106
    • A method for network monitoring includes intercepting, in an anomaly detection module, a first data packet transmitted over a network in accordance with a predefined protocol to or from an entity on the network. Both a network address that is assigned to the entity and a strong identity, which is incorporated in the first data packet in accordance with the predefined protocol, of the entity are extracted from the intercepted first data packet. An association is recorded between the network address and the strong identity. Second data packets transmitted over the network are intercepted, containing the network address. Responsively to the recorded association and the network address, the second data packets are associated with the strong identity. The associated second data packets are analyzed in order to detect anomalous behavior and to attribute the anomalous behavior to the entity.
    • 一种用于网络监控的方法包括在异常检测模块中拦截根据来自网络上的实体的预定义协议通过网络传输的第一数据分组。 从截获的第一数据包中提取分配给该实体的一个网络地址和一个与实体相关联的根据预定义协议的第一数据包中的强身份。 在网络地址和强身份之间记录关联。 通过网络传输的第二个数据包被拦截,包含网络地址。 响应于记录的关联和网络地址,第二数据分组与强身份相关联。 分析相关的第二数据包以便检测异常行为并将异常行为归因于实体。