发明名称 System and method for reducing false positives during detection of network attacks
摘要 <p>Disclosed are systems and methods for reduction of false positives during detection of network attacks on a protected computer. In one example, the system comprises a proxy device configured to redirect and mirror traffic directed to the protected computer; a traffic sensor configured to collect statistical information about the mirrored traffic; a data collector configured to aggregate information collected by the traffic sensor and to generate traffic filtering rules based on the aggregated statistical information; a filtering center configured to, in parallel with collection of statistical information, filter redirected traffic based on the traffic filtering rules provided by the data collector; and a control module configured to collect and store statistical information about known network attacks and to correct traffic filtering rules used by the filtering center for purpose of reducing false positives during detection of network attacks on the protected computer.</p>
申请公布号 EP2528005(B1) 申请公布日期 2015.06.17
申请号 EP20120151223 申请日期 2012.01.16
申请人 KASPERSKY LAB, ZAO 发明人 GUDOV, NIKOLAY V.;LEVASHOV, DMITRY A.
分类号 G06F21/00;H04L29/06 主分类号 G06F21/00
代理机构 代理人
主权项
地址