发明名称 SECURITY APPARATUS FOR THREATS DETECTION IN THE ENTERPRISE INTERNAL COMPUTATION ENVIRONMENT
摘要 The present invention relates to a security architecture for threat detection in an internal enterprise computation environment, comprising: an information collection unit which comprises a traffic information collection sensor for collecting information on all traffics flowing through a network, a RAW packet collection sensor for storing all traffics transmitted from the network as packets, and an executable file analyzer for recombining and analyzing the contents of an executable file from network packets; an information analysis unit which comprises a log collection unit for collectively storing all logs collected by the information collection unit, a log correlation analyzer for analyzing correlations between logs collected by the log collection unit, and an integrated dashboard for providing a current status of the network analyzed by the log correlation analyzer to security personnel; and an infringement incident management unit which comprises a malicious code infected PC analysis unit for determining the status for malicious codes infection of an internal enterprise network, and an infringement incident response status management unit for storing the respond status for an infringement incident from start to finish. The present invention analyzes all communications from the interior to the exterior using a protocol analyzer, and, in order to detect zero day type malicious codes introduced into the internal enterprise network, collects all executable files from all communications to implement behavior-based analysis, thereby resolving limitations of traditional technologies such as detection dependent on specific protocol, detection dependent on specific service, easy-to-detour signature-based detection, abnormality detection for network infrastructure, and detection specified for service network.
申请公布号 KR101518233(B1) 申请公布日期 2015.05.12
申请号 KR20140038101 申请日期 2014.03.31
申请人 SOONCHUNHYANG UNIVERSITY INDUSTRY ACADEMY COOPERATION FOUNDATION 发明人 KWAK, JIN;SEO, JIN WON
分类号 H04L12/22;H04L12/24;H04L12/26 主分类号 H04L12/22
代理机构 代理人
主权项
地址