发明名称 |
APPARATUS FOR DETECTING INTRUSION USING PATTERN AND METHOD THEREOF |
摘要 |
An apparatus and a method for detecting an intrusion using a pattern are provided to increase a processing speed by considerably reducing an overload caused as whether a packet is harmful is inspected by every rule whenever a packet is inputted. A rule generating unit(103) classifies intrusion detection rules into rules having a contents inspection part and rules not having the contents inspection part, assigns an index to respective rules, and outputs the same to a device that performs matching, and at the same time, stores them. An extracting unit(101) extracts a payload and an address of a packet, and outputs the same to the device. An inspecting unit(105) inspects a corresponding rule based on the index. The rule generating unit patternizes an IP address part with respect to the rules without the contents inspection part, among the intrusion detection rules.
|
申请公布号 |
KR100772523(B1) |
申请公布日期 |
2007.11.01 |
申请号 |
KR20060072649 |
申请日期 |
2006.08.01 |
申请人 |
ELECTRONICS AND TELECOMMUNICATIONS RESEARCH INSTITUTE |
发明人 |
LIM, JAE DEOK;KIM, YOUNG HO;RYU, SEUNG HO;CHUNG, BO HEUNG;KIM, KI YOUNG |
分类号 |
H04L12/22;G06F15/16;H04L12/28 |
主分类号 |
H04L12/22 |
代理机构 |
|
代理人 |
|
主权项 |
|
地址 |
|