发明名称 Method for detection of malign instrusions in a communication system and related detector
摘要 A method is proposed for detection of malign intrusions in a communication system in which flows of streaming data are monitored by means of a processing module in which a set of streaming data points has been sequentially inputted into a processing module in order to calculate a first value of a self-similarity degree. Furthermore, said first value of self-similarity degree is calculated by means of a plurality (index k) of auxiliary variables, wherein said index (k ‰¥ 1) is continuously incremented for each new fed data point. Furthermore, a new streaming data point is fed into a corresponding modified estimator (= mE) comprising the processing module that runs under a first mode wherein a second actualized value of the self-similarity degree is newly calculated. Now and according to a (possibly pre-definable) finite number n of data points, the processing module provides a windowed based calculating mode which is activated (or activable) by incoming of the new streaming data point if the index k is at least equal to the finite number n and wherein at least the oldest data point having been fed/inputted in the processing module is excluded from the processing module. According to the same scheme, by further new streaming and inputted data points, further actualized values of the self-similarity degree are calculated under the said windowed based calculating mode, wherein the finite number n has been selected in order to detect a (possibly presumed or predictable) suspected variation of actualized values within a "shifting" time interval wherein the variation and the time interval are deterministic for at least one kind of malign intrusion.
申请公布号 EP1983714(A1) 申请公布日期 2008.10.22
申请号 EP20070008085 申请日期 2007.04.20
申请人 NOKIA SIEMENS NETWORKS OY 发明人 FREIRE, MARO;GARCIA, NUNO;HAJDUCZENIA, MAREK;INACIO, PEDRO;MONTEIRO, PAULO;SILVA, HENRIQUE
分类号 H04L29/06;H04L12/26 主分类号 H04L29/06
代理机构 代理人
主权项
地址