会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 5. 发明申请
    • APPARATUS AND METHOD FOR DETECTING ANOMALOUS TRAFFIC
    • 用于检测异常交通的装置和方法
    • US20090138590A1
    • 2009-05-28
    • US12103266
    • 2008-04-15
    • Eun Young LEESeung Hyun PAEKIn Sung PARKJoo Beom YUNKi Wook SOHN
    • Eun Young LEESeung Hyun PAEKIn Sung PARKJoo Beom YUNKi Wook SOHN
    • G06F15/173
    • H04L63/1425H04L43/045
    • An apparatus and method for detecting anomalous traffic are provided. More particularly, an apparatus and method for detecting anomalous traffic based on entropy of network traffic are provided. The apparatus of detecting anomalous traffic includes: an entropy extraction module for extracting entropy from network traffic; a visualization module for generating an entropy graph based on the entropy; a graph model experience module for updating a graph model for each network attack based on the entropy graph; and an anomalous traffic detection module for detecting anomalous traffic based on the entropy graph and the graph model for each network attack and outputting the detection results to a user. In the apparatus and method, anomalous traffic is detected based on network entropy rather than simple statistics based on the amount of traffic, so that a false alarm rate of the apparatus for detecting anomalous traffic can be reduced.
    • 提供了一种用于检测异常流量的装置和方法。 更具体地,提供了一种用于基于网络流量熵来检测异常业务的装置和方法。 检测异常流量的装置包括:熵抽取模块,用于从网络流量提取熵; 用于基于所述熵产生熵图的可视化模块; 用于基于熵图更新每个网络攻击的图形模型的图形模型体验模块; 以及用于根据每个网络攻击的熵图和图形模型检测异常流量的异常流量检测模块,并将检测结果输出给用户。 在装置和方法中,基于网络熵而不是基于业务量的简单统计来检测异常业务,从而可以减少用于检测异常业务的装置的误报率。