发明名称 DEVICE FOR ANALYZING AND DIAGNOSING NETWORK TRAFFIC, A SYSTEM FOR ANALYZING AND DIAGNOSING NETWORK TRAFFIC, AND A SYSTEM FOR TRACING NETWORK TRAFFIC
摘要 A system detects the presence of illegal access attacks. The device for analyzing and diagnosing network traffic divides packets into k (k>0) types based on protocol type and port number, etc., a component observing the number of distinct values of one or more pre-specified fields in packet header for each packet type, for all packets that have transited the observation points in a network, an element observing the number of distinct values of one or more pre-specified fields in the packet payload for each packet type, for all packets that have transited the observation points in a network, and a diagnosis element determining whether the network is abnormal when the number of distinct values observed in fields of each packet type crosses a specified ratio-threshold within a predetermined interval. This enables detection of small-scale DoS attacks with little change in addresses number, improving illegal access detection accuracy.
申请公布号 US2011317566(A1) 申请公布日期 2011.12.29
申请号 US20070161139 申请日期 2007.01.16
申请人 KEENI GLENN MANSFIELD 发明人 KEENI GLENN MANSFIELD
分类号 H04L12/26 主分类号 H04L12/26
代理机构 代理人
主权项
地址