发明名称 METHOD AND APPARATUS OF DETECTING ADVANCED PERSISTENT THREAT
摘要 The present invention relates to an apparatus and method for detecting an advanced persistent threat (APT) and, more particularly, to an apparatus and method for providing early warning, in which an Internet service provider (ISP) priorly detects a sign of an APT attack in a network, and takes an action before an accident occurs. According to the present invention, the apparatus for priorly detecting the APT comprises: a node risk calculation unit for calculating a synthetic risk degree with respect to each of the nodes included in a network; a target setting unit for setting at least one target node which is attempted to be protected from the APT among the nodes based on the calculated synthetic risk degree by the node, and at least one among safety distance, an allowable risk degree, and a minimum allowable risk degree with respect to the target node; an attack sign detecting unit for detecting an attack sign within the safety distance of the target node; and a security warning unit for notifying the detected attack sign.
申请公布号 KR20150133368(A) 申请公布日期 2015.11.30
申请号 KR20140059842 申请日期 2014.05.19
申请人 KT CORPORATION 发明人 PARK, SUNG CHEOL;MOON, HO KUN;KIM, BONG KI
分类号 H04L12/22;H04L12/26 主分类号 H04L12/22
代理机构 代理人
主权项
地址