发明名称 Detection of an attack such as a pre-attack on a computer network
摘要 A computer program detects a potential attack on a computer network. A list E is made from network traffic data including source and destination addresses of traffic on the network. The list E includes all source addresses in the data which are not allocated to the network and are not in a list X. A first address in list E is chosen. A number of data entries including A and B and representing network traffic passing between source address A, chosen from list E, and destination address B, allocated to the network, is counted. If the number of such data entries is more than T, address A is output, thereby identifying address A as a potential source of attack. If it is determined that any entries in list E are left, the next address in list E is moved to, and the counting, outputting and determining is repeated, otherwise, stopping.
申请公布号 US6772349(B1) 申请公布日期 2004.08.03
申请号 US20000563548 申请日期 2000.05.03
申请人 3COM CORPORATION 发明人 MARTIN HAMISH D S;BROWN RONALD;PEARCE MARK A
分类号 H04L29/06;(IPC1-7):H04L9/00;G06F15/173 主分类号 H04L29/06
代理机构 代理人
主权项
地址