发明名称 Network-based attack tracing system and method using distributed agent and manager system
摘要 Disclosed is a network-based attack tracing system and method using a distributed attack detection agent and manager system that can detect and trace an attack path of a hacker in real time on the whole network using distributed network-based attack detection agent, request manager, and reply manager. The agent detects an attack using a network-based intrusion detection system (NIDS), analyzes an alarm log that is judged to be the attack, changes the analyzed alarm log into attack information, and transmits the attack information to the request manager. The request manager performs a search of an attack IP based on the attack information received from the agent, stores a result of search in a tree structure, and if a final search is completed, extracts a hacking path using a binary search tree (BST) algorithm. The reply manager searches an alarm log DB located in the agent of its own network in response to the attack information search request from the request manager, and transmits a result of search to the request manager. The system and method can use the detection function of the existing NIDS at maximum, control unnecessary tracing requests during the process of judging many alarm logs as the attack logs, and broaden its application range in case of the authenticated network.
申请公布号 US2003159069(A1) 申请公布日期 2003.08.21
申请号 US20020273139 申请日期 2002.10.18
申请人 CHOI BYEONG CHEOL;CHOI YANG SEO;KANG DONG HO;SEO DONG IL;SOHN SUNG WON;PARK CHEE HANG 发明人 CHOI BYEONG CHEOL;CHOI YANG SEO;KANG DONG HO;SEO DONG IL;SOHN SUNG WON;PARK CHEE HANG
分类号 H04L12/22;G06F21/00;H04L29/06;(IPC1-7):G06F11/30 主分类号 H04L12/22
代理机构 代理人
主权项
地址