发明名称 Monitoring device and monitoring method
摘要 A monitoring device to operate as a first monitoring device in a network including communication devices and monitoring devices, the monitoring device includes: an acquisition unit to acquire information of packets transmitted or received by a first communication device monitored by the first monitoring device; a transmission unit to transmit a first join request message to a first multicast group in which a second monitoring device performs notification of communication information of a second communication device monitored by the second monitoring device, when the first communication device communicates with the second communication device, after the first communication device communicates with an external device not included in the network; and a determination unit to determine whether the external device is performing unauthorized access to the second communication device via the first communication device, based on packets transmitted from the second monitoring device to the first multicast group.
申请公布号 US9560058(B2) 申请公布日期 2017.01.31
申请号 US201514722639 申请日期 2015.05.27
申请人 FUJITSU LIMITED 发明人 Kako Masaharu
分类号 H04L29/06;H04L12/18 主分类号 H04L29/06
代理机构 Staas & Halsey LLP 代理人 Staas & Halsey LLP
主权项 1. A monitoring device to operate as a first monitoring device in a network including a plurality of communication devices and a plurality of monitoring devices, the monitoring device comprising: an acquisition unit configured to acquire information of packets transmitted or received by a first communication device monitored by the first monitoring device; a transmission unit configured to transmit a first join request message to a first multicast group in which a second monitoring device performs notification of communication information of a second communication device monitored by the second monitoring device, wherein the first join request message is transmitted in response to (i) the first communication device communicating with the second communication device via intra-network communications and (ii) the first communication device subsequently communicating with an external device outside of the network after communicating with the second communication device; and a determination unit configured to determine whether the external device is performing unauthorized access to the second communication device via the first communication device, based on packets being transmitted from the second monitoring device to the first multicast group and collected from the notification of communication information corresponding to the first join request message sent by the first monitoring device.
地址 Kawasaki JP