会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 2. 发明公开
    • 시그니처 패턴 매칭방법과 그 시스템 및 시그니처 패턴이기록된 기록매체
    • 签名模式匹配方法,相同系统和计算机可读介质存储签名模式
    • KR1020090065306A
    • 2009-06-22
    • KR1020070132796
    • 2007-12-17
    • 한국전자통신연구원
    • 이성원문화신박상길오진태장종수신영찬
    • G06F21/00
    • H04L63/1416H04L41/0604H04L41/0631
    • A signature pattern matching method, a system for the same and a computer readable medium storing a signature pattern are provided to reduce the amount of memory use by minimizing a memory access time based on the usage of a bloom filter. The sub string of a traffic packet is extracted(S100), and a hash value is obtained by applying a hash function to the extracted sub string(S110). A pre-filtering that checks membership is performed(S120), and a bloom filter which is supposed to be compared with a currently-obtained harsh value is queried(S130). It is checked over whether or not a pattern matched with the queried bloom filter exists(S140), and it is checked over whether or not a signature completion filed is included to the sub string of the matched signature pattern(S150).
    • 提供签名模式匹配方法,用于其的系统和存储签名模式的计算机可读介质,以通过基于布隆过滤器的使用最小化存储器访问时间来减少存储器使用量。 提取业务分组的子串(S100),并通过对所提取的子串应用散列函数来获得散列值(S110)。 执行检查成员资格的预过滤(S120),并且查询应该与当前获得的苛刻值进行比较的大写过滤器(S130)。 检查是否存在与查询的布隆过滤器匹配的模式(S140),并且检查签名完成归档是否包括在匹配签名模式的子串中(S150)。
    • 7. 发明公开
    • 증거 수집 방법 및 장치
    • 收集证据的方法和装置
    • KR1020110020051A
    • 2011-03-02
    • KR1020090077732
    • 2009-08-21
    • 한국전자통신연구원
    • 김기범황현욱신영찬장태주이철원백승재
    • G06F15/00G06F11/00G06F17/30
    • G06Q10/10
    • PURPOSE: A collection evidence method and an apparatus thereof, capable of collecting a used file and an access file are provided to maximize the validity of the evidence collection by collecting the used file through the analysis of a link file. CONSTITUTION: An access module(200) accesses a storage medium of a target computer. A file system analysis module(300) analyzes a file system of the storage medium. A link analysis module(500) analyzes a link file through the file system analysis module. A raw file extracting module(600) extracts the original file by using path of the original file. A UI(User Interface) module(800) displays the content of the original file and link information.
    • 目的:提供能够收集使用的文件和访问文件的收集证据方法及其装置,以通过分析链接文件收集使用的文件来最大化证据收集的有效性。 构成:访问模块(200)访问目标计算机的存储介质。 文件系统分析模块(300)分析存储介质的文件系统。 链接分析模块(500)通过文件系统分析模块分析链接文件。 原始文件提取模块(600)通过使用原始文件的路径提取原始文件。 UI(用户界面)模块(800)显示原始文件和链接信息的内容。
    • 8. 发明公开
    • 네트워크 공격 시그너처 생성 방법 및 장치
    • 用于生成网络攻击签名的方法和装置
    • KR1020080050215A
    • 2008-06-05
    • KR1020070049869
    • 2007-05-22
    • 한국전자통신연구원
    • 이성원문화신신영찬오진태
    • G06F15/00H04L9/32
    • A method and an apparatus for generating a network attack signature are provided to improve reliability of a signature by separating a protocol header from packets or sessions, and minimize a whitelist, and a memory required for separation of the protocol header by using clustering. An apparatus for generating a network attack signature includes a sub-string extracting module(10) extracting sub-strings from input packets and dividing the sub-strings into an application header and application data to measure byte distribution of the extracted sub-strings, and a signature generating module(20) generating an attack signature from the sub-string showing frequency higher than a specific value by combining byte distribution at the application header with byte distribution at the application data.
    • 提供了一种用于生成网络攻击签名的方法和装置,以通过将协议报头与分组或会话分离,并将白名单和使用聚类分离协议报头所需的存储器最小化来提高签名的可靠性。 用于生成网络攻击签名的装置包括:子串提取模块(10),从输入包中提取子串,并将子串划分为应用头和应用数据,以测量提取的子串的字节分布,以及 签名生成模块(20),通过将应用头上的字节分布与应用数据上的字节分布组合,从表示高于特定值的频率的子串生成攻击签名。
    • 9. 发明公开
    • 백업부트레코드 정보를 이용한 파티션 복구 장치 및 방법
    • 使用备份引导记录恢复分区的方法和装置
    • KR1020140026821A
    • 2014-03-06
    • KR1020120092498
    • 2012-08-23
    • 한국전자통신연구원
    • 황현욱김기범이승용신영찬장태주
    • G06F12/16G06F11/00
    • G06F11/1435G06F11/1417G06F17/30117
    • Disclosed is a partition recovering method using backup boot record information comprising the steps of: classifying an unallocated area on a disk or a proof image; searching the position of a backup boot record in the unallocated area; analyzing whether a backup boot record of a file system to be searched exists among searched sectors; in case the backup boot record is the backup boot record of the file system to be searched, determining whether the backup boot record is a boot record of an effective partition; and, in case the backup boot record is the boot record of an effective partition, parsing a file system of a deleted partition using the backup boot record, and recovering deleted directories and files. [Reference numerals] (10) Disk; (20) Proof image; (30) Access part; (40) File system construction part; (50) Sector map construction part; (60) Backup boot record search part; (70) Partition certification part; (80) File system generation part; (90) User interface part
    • 公开了一种使用备份引导记录信息的分区恢复方法,包括以下步骤:对盘上的未分配区域或证明图像进行分类; 在未分配区域中搜索备份启动记录的位置; 分析搜索到的扇区之间是否存在要搜索的文件系统的备份启动记录; 如果备份引导记录是要搜索的文件系统的备份引导记录,则确定备份引导记录是否是有效分区的引导记录; 并且,如果备份引导记录是有效分区的引导记录,则使用备份引导记录解析已删除分区的文件系统,并恢复已删除的目录和文件。 (附图标记)(10)盘; (20)证明图像; (30)访问部分; (40)文件系统构建部分; (50)部门图施工部分; (60)备份启动记录搜索部分; (70)分区认证部分; (80)文件系统生成部分; (90)用户界面部分