发明名称 APPLYING BLOCKING MEASURES PROGRESSIVELY TO MALICIOUS NETWORK TRAFFIC
摘要 A method of progressive response for invoking and suspending blocking measures that defend against network anomalies such as malicious network traffic so that false positives and false negatives are minimized. When an anomaly is detected, the detector notifies protective equipment such as a firewall or a router to invoke a blocking measure. The blocking measure is maintained for an initial duration, after which it is suspended while another test for the anomaly is made. If the anomaly is no longer evident, the method returns to the state of readiness. Otherwise, a loop is executed to re-applying the blocking measure for a specified duration, then suspend the blocking measure and test again for the anomaly. If the anomaly is detected, the blocking measure is re-applied, and its duration is adapted. If the anomaly is no longer detected, the method returns to the state of readiness.
申请公布号 US2008072326(A1) 申请公布日期 2008.03.20
申请号 US20070871188 申请日期 2007.10.12
申请人 DANFORD ROBERT W;FARMER KENNETH M;JEFFRIES CLARK D;SISK ROBERT B;WALTER MICHAEL A 发明人 DANFORD ROBERT W.;FARMER KENNETH M.;JEFFRIES CLARK D.;SISK ROBERT B.;WALTER MICHAEL A.
分类号 G06F21/00;G06F11/30;H04L29/06 主分类号 G06F21/00
代理机构 代理人
主权项
地址