会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 4. 发明申请
    • NETWORK-BASED INTERNET WORM DETECTION APPARATUS AND METHOD USING VULNERABILITY ANALYSIS AND ATTACK MODELING
    • 基于网络的互联网检测装置和使用易受攻击性分析和攻击建模的方法
    • US20080104702A1
    • 2008-05-01
    • US11685940
    • 2007-03-14
    • Yang Seo CHOIDae Won KIMIk Kyun KIMJin Tae OH
    • Yang Seo CHOIDae Won KIMIk Kyun KIMJin Tae OH
    • G06F11/00
    • H04L63/145
    • The present invention relates to a network-based Internet worm detection apparatus and method using vulnerability analysis and attack modeling. In the network-based Internet worm detection apparatus, a vulnerability information storage unit stores the vulnerability information of an application program that is necessary for attack detection. A threat determiner determines whether a packet transmitted over a network is destined for a vulnerable application program with vulnerability. A packet content extractor extracts, using the vulnerability information, information for determination of an attack packet from the packet determined to be destined for the vulnerable application program. An attack determiner compares and analyzes the extracted information and the vulnerability information to determine whether the packet is an attack packet. The vulnerability information of the application program and attack modeling are used to detect an Internet worm, thereby making it possible to counteract the attack packet. In addition, only a portion of information belonging to a specific session of a segmented or disordered packet is stored, thereby making it possible to increase the use efficiency of a storage device and to reduce the resource necessary for processing a packet.
    • 本发明涉及一种使用漏洞分析和攻击建模的基于网络的互联网蠕虫检测装置和方法。 在基于网络的互联网蠕虫检测装置中,漏洞信息存储单元存储攻击检测所必需的应用程序的漏洞信息。 威胁确定器确定通过网络发送的数据包是否发往具有漏洞的易受攻击的应用程序。 分组内容提取器使用该漏洞信息提取用于确定来自确定为易受攻击的应用程序的分组的分组的攻击分组的信息。 攻击确定器比较和分析提取的信息和漏洞信息,以确定数据包是否是攻击数据包。 应用程序的漏洞信息和攻击建模用于检测Internet蠕虫,从而可以抵御攻击报文。 此外,仅存储属于分段或无序分组的特定会话的信息的一部分,从而可以提高存储设备的使用效率并减少处理分组所需的资源。