会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 4. 发明申请
    • Applying blocking measures progressively to malicious network traffic
    • 对恶意网络流量逐步应用阻塞措施
    • US20060075496A1
    • 2006-04-06
    • US11283380
    • 2005-11-17
    • Brian CarpenterKevin HimbergerClark JeffriesMohammad Peyravian
    • Brian CarpenterKevin HimbergerClark JeffriesMohammad Peyravian
    • G06F12/14
    • H04L63/1458G06F21/00G06F21/552H04L69/22
    • A method of progressive response for invoking and suspending blocking measures that defend against network anomalies such as malicious network traffic so that false positives and false negatives are minimized. When a truncated secure session attack is detected, the detector notifies protective equipment such as a firewall or a router to invoke a blocking measure. The blocking measure is maintained for an initial duration, after which it is suspended while another test for the anomaly is made. If the attack is no longer evident, the method returns to the state of readiness. Otherwise, a loop is executed to re-applying the blocking measure for a specified duration, then suspend the blocking measure and test again for the attack. If the attack is detected, the blocking measure is re-applied, and its duration is adapted. If the attack is no longer detected, the method returns to the state of readiness.
    • 一种逐步响应的方法,用于调用和中止阻止网络异常(如恶意网络流量)的阻塞措施,从而最大限度地减少误报和假阴性。 当检测到截断的安全会话攻击时,检测器通知防火墙或路由器等防护设备调用阻塞措施。 阻塞措施保持初始持续时间,之后暂停,并进行另一次异常测试。 如果攻击不再明显,则该方法返回到准备状态。 否则,执行一个循环以在指定的持续时间内重新应用阻塞度量,然后暂停阻止措施并再次测试攻击。 如果检测到攻击,则重新应用阻塞措施,并适应其持续时间。 如果不再检测到攻击,该方法返回到准备状态。
    • 5. 发明申请
    • APPLYING BLOCKING MEASURES PROGRESSIVELY TO MALICIOUS NETWORK TRAFFIC
    • 应对阻塞措施进展到恶性网络交通
    • US20080072326A1
    • 2008-03-20
    • US11871188
    • 2007-10-12
    • Robert DanfordKenneth FarmerClark JeffriesRobert SiskMichael Walter
    • Robert DanfordKenneth FarmerClark JeffriesRobert SiskMichael Walter
    • G06F21/00
    • H04L63/1458
    • A method of progressive response for invoking and suspending blocking measures that defend against network anomalies such as malicious network traffic so that false positives and false negatives are minimized. When an anomaly is detected, the detector notifies protective equipment such as a firewall or a router to invoke a blocking measure. The blocking measure is maintained for an initial duration, after which it is suspended while another test for the anomaly is made. If the anomaly is no longer evident, the method returns to the state of readiness. Otherwise, a loop is executed to re-applying the blocking measure for a specified duration, then suspend the blocking measure and test again for the anomaly. If the anomaly is detected, the blocking measure is re-applied, and its duration is adapted. If the anomaly is no longer detected, the method returns to the state of readiness.
    • 一种逐步响应的方法,用于调用和中止阻止网络异常(如恶意网络流量)的阻塞措施,从而最大限度地减少误报和假阴性。 当检测到异常时,检测器通知防火墙或路由器等防护设备调用阻塞措施。 阻塞措施保持初始持续时间,之后暂停,并进行另一次异常测试。 如果异常不再明显,则返回到准备状态。 否则,执行一个循环以在特定持续时间内重新应用阻塞度量,然后暂停阻塞度量并再次测试异常。 如果检测到异常,则重新应用阻塞措施,并适应其持续时间。 如果不再检测到异常,则该方法返回到准备状态。