发明名称 METHOD AND SYSTEM FOR TRACKING ATTACK SOURCE AND ATTACK SPREADING SITE
摘要 PURPOSE: A method for tracking attack sources and attack distribution places and a system thereof are provided to manage a path and configuration for an attack scenario by tracking an abnormal file uploader in real-time. CONSTITUTION: An agent(500) receives an information confirmation message of an abnormal file corresponding to the information transmission of an abnormal file(S117). The agent selects a place corresponding to the information of the abnormal file as an attack distribution place(S119). The agent transmits an abnormal file uploader information request message. The agent receives the abnormal file uploader information corresponding to the request message(S121). When the received abnormal file uploader information corresponds to the stored uploader information, the agent sets an attack source using the abnormal file uploader information(S123). [Reference numerals] (100) Attack computer; (200) User computer; (300) Network security server; (400) Site file management server; (500) Agent; (S101) Upload an abnormal file; (S103) Analyze action and extract uploader information; (S105) Transmit the uploader information; (S107) Store the uploader information; (S109) Download abnormal file; (S111) Store downloaded user information with the uploader information; (S113) Transmit attack information when detecting cyber attack; (S115) Transmit transmission network address; (S117) Transmit confirmation message of the transmission network address; (S119) Define an attack distribution place; (S121) Receive the uploader information; (S123) Define an attack source
申请公布号 KR20130049336(A) 申请公布日期 2013.05.14
申请号 KR20110114286 申请日期 2011.11.04
申请人 ELECTRONICS AND TELECOMMUNICATIONS RESEARCH INSTITUTE 发明人 SEO, DAE HEE;AN, GAE IL;KIM, JONG HYUN;SEO, DONG IL;KIM, KI YOUNG;YI, SUNG WON;LIM, SUN HEE
分类号 H04L12/22;G06F21/00;H04L9/00 主分类号 H04L12/22
代理机构 代理人
主权项
地址