会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 1. 发明授权
    • Network attack detection devices and methods
    • 网络攻击检测设备和方法
    • US08341742B2
    • 2012-12-25
    • US12837986
    • 2010-07-16
    • Hahn-Ming LeeSi-Yu HuangJerome YehChing-Hao Mao
    • Hahn-Ming LeeSi-Yu HuangJerome YehChing-Hao Mao
    • H04L29/06
    • H04L63/1416H04L29/12066H04L61/1511
    • A network attack detection device is provided, including a spatial coordinate database for storing spatial coordinate data; a standard time zone database for storing standard time zone data; a domain name system packet collector for collecting a domain name system packet; a spatial snapshot feature extractor for extracting internet protocol address corresponding to the domain name system packet according to the domain name system packet, and generating spatial feature data corresponding to the internet protocol address according to the internet protocol address, the spatial coordinate data and the standard time zone data; and an attack detector for determining whether the domain name system packet is an attack according to the spatial feature data and a spatial snapshot detection model, and when determining that the domain name system packet is an attack, sending a warning to indicate the attack.
    • 提供一种网络攻击检测装置,包括用于存储空间坐标数据的空间坐标数据库; 用于存储标准时区数据的标准时区数据库; 用于收集域名系统包的域名系统包收集器; 空间快照特征提取器,用于根据域名系统分组提取与域名系统分组对应的互联网协议地址,并根据因特网协议地址,空间坐标数据和标准产生与互联网协议地址对应的空间特征数据 时区数据; 以及用于根据空间特征数据和空间快照检测模型来确定域名系统分组是否是攻击的攻击检测器,并且当确定域名系统分组是攻击时,发送指示攻击的警告。
    • 3. 发明申请
    • BOTNET EARLY DETECTION USING HYBRID HIDDEN MARKOV MODEL ALGORITHM
    • BOTNET早期检测使用混合隐马尔可夫模型算法
    • US20110004936A1
    • 2011-01-06
    • US12726272
    • 2010-03-17
    • Hahn-Ming LeeChing-Hao MaoYu-Jie ChenYi-Hsun WangJerome YehTsu-Han Chen
    • Hahn-Ming LeeChing-Hao MaoYu-Jie ChenYi-Hsun WangJerome YehTsu-Han Chen
    • G06F21/00
    • H04L63/1441H04L2463/144
    • A botnet detection system is provided. A bursty feature extractor receives an Internet Relay Chat (IRC) packet value from a detection object network, and determines a bursty feature accordingly. A Hybrid Hidden Markov Model (HHMM) parameter estimator determines probability parameters for a Hybrid Hidden Markov Model according to the bursty feature. A traffic profile generator establishes a probability sequential model for the Hybrid Hidden Markov Model according to the probability parameters and pre-defined network traffic categories. A dubious state detector determines a traffic state corresponding to a network relaying the IRC packet in response to reception of a new IRC packet, determines whether the IRC packet flow of the object network is dubious by applying the bursty feature to the probability sequential model for the Hybrid Hidden Markov Model, and generates a warning signal when the IRC packet flow is regarded as having a dubious traffic state.
    • 提供僵尸网络检测系统。 突发特征提取器从检测对象网络接收因特网中继聊天(IRC)分组值,并相应地确定突发特征。 混合隐马尔可夫模型(HHMM)参数估计器根据突发特征确定混合隐马尔可夫模型的概率参数。 流量简档生成器根据概率参数和预定义的网络流量类别建立混合隐马尔可夫模型的概率序列模型。 可疑状态检测器响应于接收到新的IRC分组而确定与中继IRC分组的网络相对应的业务状态,通过将突发特征应用于概率序列模型来确定对象网络的IRC分组流是否可疑, 混合隐马尔可夫模型,并且当IRC分组流被认为具有可疑业务状态时,生成警告信号。
    • 7. 发明授权
    • Botnet early detection using hybrid hidden markov model algorithm
    • 僵尸网络早期检测使用混合隐马尔可夫模型算法
    • US08307459B2
    • 2012-11-06
    • US12726272
    • 2010-03-17
    • Hahn-Ming LeeChing-Hao MaoYu-Jie ChenYi-Hsun WangJerome YehTsu-Han Chen
    • Hahn-Ming LeeChing-Hao MaoYu-Jie ChenYi-Hsun WangJerome YehTsu-Han Chen
    • G06F7/04G06F11/00
    • H04L63/1441H04L2463/144
    • A botnet detection system is provided. A bursty feature extractor receives an Internet Relay Chat (IRC) packet value from a detection object network, and determines a bursty feature accordingly. A Hybrid Hidden Markov Model (HHMM) parameter estimator determines probability parameters for a Hybrid Hidden Markov Model according to the bursty feature. A traffic profile generator establishes a probability sequential model for the Hybrid Hidden Markov Model according to the probability parameters and pre-defined network traffic categories. A dubious state detector determines a traffic state corresponding to a network relaying the IRC packet in response to reception of a new IRC packet, determines whether the IRC packet flow of the object network is dubious by applying the bursty feature to the probability sequential model for the Hybrid Hidden Markov Model, and generates a warning signal when the IRC packet flow is regarded as having a dubious traffic state.
    • 提供僵尸网络检测系统。 突发特征提取器从检测对象网络接收因特网中继聊天(IRC)分组值,并相应地确定突发特征。 混合隐马尔可夫模型(HHMM)参数估计器根据突发特征确定混合隐马尔可夫模型的概率参数。 流量简档生成器根据概率参数和预定义的网络流量类别建立混合隐马尔可夫模型的概率序列模型。 可疑状态检测器响应于接收到新的IRC分组而确定与中继IRC分组的网络相对应的业务状态,通过将突发特征应用于概率序列模型来确定对象网络的IRC分组流是否可疑, 混合隐马尔可夫模型,并且当IRC分组流被认为具有可疑业务状态时,生成警告信号。