发明名称 ESTABLISHMENT OF ALERTS BY MEANS OF THE DETECTION OF STATIC AND DYNAMIC ANOMALIES IN THE TRAFFIC OF A SERVICE ENTITY
摘要 The invention relates to the establishment of alerts using periodic evaluations of evaluation parameters relating to the traffic of at least one service entity (SE), static anomaly detectors (DDs) and dynamic anomaly detectors (DDd) in order to detect flooding-denial-type attacks, such as to produce a global alert including evaluation parameters and a current evaluation date when an alert level exceeds a minimum threshold. The global alerts of entities associated with the current evaluation date are aggregated into a current aggregated alert (AA). If the smallest similarity distance between the current aggregated alert and the alerts aggregated on evaluation dates close to the current date is lower than a similarity threshold, the identifiers of the aggregated alerts separated by the smallest distance are merged, thereby signalling a detected attack. Otherwise, an identifier is attributed to the current aggregated alert.
申请公布号 WO2007020361(A2) 申请公布日期 2007.02.22
申请号 WO2006FR50800 申请日期 2006.08.11
申请人 FRANCE TELECOM;SIBERT, HERVE;BESSON, EMMANUEL;GOUGET, ALINE 发明人 SIBERT, HERVE;BESSON, EMMANUEL;GOUGET, ALINE
分类号 H04L29/06 主分类号 H04L29/06
代理机构 代理人
主权项
地址
您可能感兴趣的专利