发明名称 METHOD AND DEVICE FOR CLASSIFYING TCP CONNECTION CARRYING HTTP TRAFFIC
摘要 For classifying a TCP connection carrying HTTP traffic as trusted or untrusted, an analyser device performs: detecting an HTTP request message of an HTTP session carried by the TCP connection; obtaining, from headers of the detected HTTP request message, information to build a signature of the HTTP session; comparing the built signature with signatures stored beforehand in a signatures database; classifying the TCP connection as trusted, when the built signature matches a signature that is stored beforehand in the signatures database and that is representative of a trusted HTTP client application; performing an authentication procedure, when the built signature does not match any signature stored beforehand in the signatures database, the authentication procedure requesting a user to provide authentication data; adding the built signature in the signatures database, when valid authentication data are provided by the user, the signature of the HTTP session being representative in the signatures database of a trusted HTTP client application, and classifying the TCP connection as trusted; and otherwise, classifying the TCP connection as untrusted.
申请公布号 WO2015133557(A1) 申请公布日期 2015.09.11
申请号 WO2015JP56443 申请日期 2015.02.26
申请人 MITSUBISHI ELECTRIC CORPORATION;MITSUBISHI ELECTRIC R&D CENTRE EUROPE B.V. 发明人 ROLLET, ROMAIN
分类号 H04L29/06;H04L12/851 主分类号 H04L29/06
代理机构 代理人
主权项
地址