发明名称 DETECTING PAST INTRUSIONS AND ATTACKS BASED ON HISTORICAL NETWORK TRAFFIC INFORMATION
摘要 A device may receive information that identifies an attack signature for detecting an intrusion. The device may determine a device configuration that is vulnerable to the intrusion, may determine an endpoint device associated with the device configuration, and may determine a time period during which the endpoint device was associated with the device configuration. The device may determine an endpoint identifier associated with the endpoint device during the time period, and may identify network traffic information associated with the endpoint identifier during the time period. The device may apply the attack signature to the network traffic information, and may determine whether the endpoint device was subjected to the intrusion during the time period based on applying the attack signature to the network traffic information. The device may selectively perform an action based on determining whether the endpoint device was subjected to the intrusion.
申请公布号 US2017041334(A1) 申请公布日期 2017.02.09
申请号 US201615299991 申请日期 2016.10.21
申请人 Juniper Networks, Inc. 发明人 KAHN Clifford E.;Hanna Stephen R.
分类号 H04L29/06 主分类号 H04L29/06
代理机构 代理人
主权项
地址 Sunnyvale CA US