发明名称 Apparatuses and methods for detecting anomalous event in network
摘要 IP state-vector manager determines state vector value by updating token numbers of IP state vector according to source and destination IP addresses of the received packet, and obtains state number of state vector value by counting state vector value. Port-number state-vector manager determines state vector value by updating token numbers of port-number state vector according to source and destination token numbers of packet, and obtains state number of state vector value by counting state vector value. Entropy calculator calculates entropies related to IP address and port number, based on number and state number of state vector values related to IP state vector and port-number state vector. Anomalous event determiner determines whether there is anomalous event in network based on calculated entropies. Anomalous event can be efficiently detected with minimized false negative and positive rates.
申请公布号 US8144603(B2) 申请公布日期 2012.03.27
申请号 US20100685736 申请日期 2010.01.12
申请人 CHOI HYOUNG-KEE;HAN CHAN-KYU;SUNGKYUNKWAN UNIVERSITY FOUNDATION FOR CORPORATE COLLABORATION 发明人 CHOI HYOUNG-KEE;HAN CHAN-KYU
分类号 H04L1/00 主分类号 H04L1/00
代理机构 代理人
主权项
地址