发明名称 INTRUSION PREVENTION APPARATUS BASED ON ALERT SEVERITY OF SIGNITURE DETECTION AND ABNORMAL TRAFFIC AND METHOD THEREOF
摘要 An apparatus and a method for preventing intrusion based on alert severity of signature detection and abnormal traffic are provided to calculate exact reliability of the alert severity of an abnormal traffic detecting sensor by using attack alerts collected form different kinds of detecting sensors, thereby properly dealing with the intrusion with respect to the abnormal traffic. A preprocessor(120) classifies attack alerts each having reliability and alarm severity, collected from different plural attack pattern detecting sensors(101) and an abnormal traffic detecting sensor(105), according to generation time and calculates a reference value showing consistency of attack alerts having the same generation time. A reliability calculator(130) calculates reliability of alarm severity of attack alerts generated by the abnormal traffic detecting sensor based on at least one of the reference value and alert severity of the attack alerts generated at the same time. A reliability calculator(130) calculates the reliability of alarm risk for an attack alarm, which is generated by the abnormal traffic detecting sensor, based on at least one of either the reference value calculated by the preprocessor or the alarm risk for attack alarms which occur at the same time.
申请公布号 KR100809422(B1) 申请公布日期 2008.03.05
申请号 KR20060096454 申请日期 2006.09.29
申请人 ELECTRONICS AND TELECOMMUNICATIONS RESEARCH INSTITUTE 发明人 CHEONG, IL AHN;NAM, TAEK YONG;OH, JIN TAE;JANG, JONG SOO
分类号 H04L12/22;G06F15/16;H04L12/26 主分类号 H04L12/22
代理机构 代理人
主权项
地址