发明名称 Scan detection
摘要 A method for detecting a scan in network connections, each connection to a respective destination determined by a destination key and a destination parameter. For each of the connections, an active-connection entry is logged in a first table. The active-connection entry includes the destination key and the destination parameter. For each destination key entered in the first table, each active-connection entry is counted by: (i) entering in a second table a new-connection entry including the destination key, and (ii) assigning to the new-connection entry a use value; the use value equals a number of the active-connection entries with the destination key. A scan event is generated when the use value exceeds a previously determined new-connection-threshold. If the scan is an "address scan", the destination key is a destination port and the destination parameter is a destination address (IP); and if the scan is a "port scan" then the destination key is a destination address and the destination parameter is a destination port.
申请公布号 US2005147037(A1) 申请公布日期 2005.07.07
申请号 US20050025983 申请日期 2005.01.03
申请人 CHECK POINT SOFTWARE TECHNOLOGIES LTD. 发明人 MAIMON URIEL;KANTOR ALON;DOV ODED B.
分类号 G06F11/30;G06F15/16;H04L1/00;H04L29/06;(IPC1-7):H04L1/00 主分类号 G06F11/30
代理机构 代理人
主权项
地址