发明名称 OFFLINE ANALYSIS OF PACKETS
摘要 <p>A method, apparatus, system, and signal-bearing medium that, in an embodiment, filter packets received from a network based on rules. The filtering discards a subset of the packets based on the rules and keeps a remaining subset of the packets. The remaining subset is copied to a destination. The rules are created offline in a lower priority process from the filtering and copying by detecting whether symptoms exist in a sample of the remaining subset. In an embodiment, the order that the symptoms are detected is changed based on the frequency of the existence of the symptoms in the sample. In various embodiments, the symptoms may include receiving a threshold number of ping packets within a time period, receiving a threshold number of broadcast packets within a time period, receiving a packet with an invalid source address, receiving a packet with an invalid header flag, and receiving a threshold number of the packets within a time period that contain a sequence flag. In this way, firewall throughput performance is increased.</p>
申请公布号 WO2006037809(A1) 申请公布日期 2006.04.13
申请号 WO2005EP55096 申请日期 2005.10.07
申请人 INTERNATIONAL BUSINESS MACHINES CORPORATION;IBM UNITED KINGDOM LIMITED;KHOSMOOD, FOAAD;PETROVIC, OGNJEN;SAVOY, JEREMY, MATTHEW;WOODS, DUNCAN, ALLEN 发明人 KHOSMOOD, FOAAD;PETROVIC, OGNJEN;SAVOY, JEREMY, MATTHEW;WOODS, DUNCAN, ALLEN
分类号 H04L29/06 主分类号 H04L29/06
代理机构 代理人
主权项
地址