发明名称 Real-time network attack pattern detection system for unknown network attack and method thereof
摘要 The present invention relates to a real-time network attack pattern detection system and a method thereof in which a common pattern is detected in real time from packets, which are suspected to be a network attack such as Worm, to effectively block the attack. The system includes: a suspicious packet detector for classifying a suspicious attack packet from all input packets; a first data delaying unit for receiving the input packet from the suspicious packet detector to output an one-clock delayed data; a second data delaying unit for receiving an output signal from the first data delaying unit to output an one-clock delayed data; a hash key generator for receiving an output data of the suspicious packet detector, an output data of the first data delaying unit and an output data of the second data delaying unit to generate a hash key; a hash table for storing a lookup result obtained by the hash key generated from the hash key generator; and an existence & hit checker for checking the lookup result of the hash table.
申请公布号 US2006123480(A1) 申请公布日期 2006.06.08
申请号 US20050088975 申请日期 2005.03.24
申请人 ELECTRONICS AND TELECOMMUNICATIONS RESEARCH INSTITUTE 发明人 OH JINTAE;SHIN SEUNG W.;KIM KI Y.;JANG JONG S.;SOHN SUNG W.
分类号 G06F12/14 主分类号 G06F12/14
代理机构 代理人
主权项
地址