发明名称 METHOD AND DEVICE FOR DETECTING AND BLOCKING UNAUTHORIZED ACCESS
摘要 PROBLEM TO BE SOLVED: To detect unauthorized traffic misrepresenting a port number of TCP or UDP, unauthorized traffic in encrypted or encapsulated traffic and novel illicit traffic sent by a computer virus or an illicit user. SOLUTION: The disclosed device comprises: a flow feature list storage section 29 for storing the expected value of a behavior for the traffic for each port number (e.g., average value and variance value of packet lengths, average value and variance value of packet arrival time intervals), a receiving section 26 for receiving the traffic and separating it into data packets; calculation sections 21-24, 30-35 for measuring the behavior of the individually separated traffic; a port number detection section 25 for detecting the port number of a data packet; and a flow comparing section 28 for comparing the measured behavior with the expected value stored in the flow feature list storage section 29 based on the detected port number, and determining the unauthorized traffic. COPYRIGHT: (C)2007,JPO&INPIT
申请公布号 JP2006279930(A) 申请公布日期 2006.10.12
申请号 JP20060026872 申请日期 2006.02.03
申请人 NEC CORP 发明人 KITAMURA TSUTOMU;OKABE TOSHIYA
分类号 H04L12/66;G06F13/00 主分类号 H04L12/66
代理机构 代理人
主权项
地址