发明名称 METHODS AND SYSTEMS FOR AUTOMATED DETECTION AND TRACKING OF NETWORK ATTACKS
摘要 Methods for tracking attacking nodes are described and include extracting, from a database, an instance of each unique packet header associated with IP-to-IP packets transmitted over a time period. The method includes determining from extracted headers, which nodes have attempted to establish a connection with an excessive number of other nodes over a period, identifying these as potential attacking nodes, determining from the headers, which other nodes responded with a TCP SYN/ACK packet indicating a willingness to establish connections, and a potential for compromise. Nodes scanned by potential attacking nodes are disqualified from the identified nodes based on at least one of: data in the headers relating to at least one of an amount of data transferred, and scanning activities conducted by the nodes that responded to a potential attacking node with a TCP SYN/ACK packet. Any remaining potential attacking nodes and scanned nodes are presented to a user.
申请公布号 US2010050262(A1) 申请公布日期 2010.02.25
申请号 US20080195359 申请日期 2008.08.20
申请人 KNAPP STEPHEN;ALDRICH TIMOTHY MARK 发明人 KNAPP STEPHEN;ALDRICH TIMOTHY MARK
分类号 G06F21/00 主分类号 G06F21/00
代理机构 代理人
主权项
地址