发明名称 METHOD AND APPARATUS FOR CLASSIFYING HARMFUL PACKET
摘要 A network apparatus and method of classifying received packets based on a predetermined standard are disclosed. The method of classifying received packets in a security system, the method comprises parsing a received packet and extracting a payload from the parsed packet; scanning the payload to check whether or not a predetermined signature code is included in the payload; if it is determined from the result of the scanning that the predetermined signature code is included in the payload, generating a presumptive signature based on information included in the predetermined signature code; and determining whether or not the generated presumptive signature is identical with a signature corresponding to the predetermined signature code, and allocating an classification identifier (ID) to the received packet according to the result of the determination, thereby classifying the received packet according to the classification ID, wherein the predetermined signature code is formed by a part of the signature corresponding to the signature code. Accordingly, possible harmful packets such as attack packets can be classified at high speed, and thereby being blocked immediately.
申请公布号 US2010251364(A1) 申请公布日期 2010.09.30
申请号 US20090410975 申请日期 2009.03.25
申请人 SYSMATE CO., LTD. 发明人 LEE HOSUG;KIM MYEONG-SEOK
分类号 G06F11/00 主分类号 G06F11/00
代理机构 代理人
主权项
地址