发明名称 NETWORK DEFENSE SYSTEM AND FRAMEWORK FOR DETECTING AND GEOLOCATING BOTNET CYBER ATTACKS
摘要 A network defense system is described that provides network sensor infrastructure and a framework for managing and executing advanced cyber security algorithms specialized for detecting highly-distributed, stealth network attacks. In one example, a system includes a data collection and storage subsystem that provides a central repository to store network traffic data received from sensors positioned within geographically separate networks. Cyber defense algorithms analyze the network traffic data and detect centrally-controlled malware that is configured to perform distributed network attacks ("botnet attacks") from devices within the geographically separate networks. A visualization and decision-making subsystem generates a user interface that presents an electronic map of geographic locations of source devices and target devices of the botnet attacks. The data collection and storage subsystem stores a manifest of parameters for the network traffic data to be analyzed by each of the cyber defense algorithms.
申请公布号 US2013174256(A1) 申请公布日期 2013.07.04
申请号 US201213730706 申请日期 2012.12.28
申请人 ARCHITECTURE TECHNOLOGY CORPORATION;ARCHITECTURE TECHNOLOGY CORPORATION 发明人 POWERS JUDSON
分类号 H04L29/06 主分类号 H04L29/06
代理机构 代理人
主权项
地址