发明名称 Apparatus and method for detecting anomalous traffic
摘要 An apparatus and method for detecting anomalous traffic are provided. More particularly, an apparatus and method for detecting anomalous traffic based on entropy of network traffic are provided. The apparatus of detecting anomalous traffic includes: an entropy extraction module for extracting entropy from network traffic; a visualization module for generating an entropy graph based on the entropy; a graph model experience module for updating a graph model for each network attack based on the entropy graph; and an anomalous traffic detection module for detecting anomalous traffic based on the entropy graph and the graph model for each network attack and outputting the detection results to a user. In the apparatus and method, anomalous traffic is detected based on network entropy rather than simple statistics based on the amount of traffic, so that a false alarm rate of the apparatus for detecting anomalous traffic can be reduced.
申请公布号 US7716329(B2) 申请公布日期 2010.05.11
申请号 US20080103266 申请日期 2008.04.15
申请人 ELECTRONICS AND TELECOMMUNICATIONS RESEARCH INSTITUTE 发明人 LEE EUN YOUNG;PAEK SEUNG HYUN;PARK IN SUNG;YUN JOO BEOM;SOHN KI WOOK
分类号 G06F13/00 主分类号 G06F13/00
代理机构 代理人
主权项
地址