- 专利标题: Active network defense system and method
-
申请号: US10930392申请日: 2004-08-31
-
公开(公告)号: US20050044422A1公开(公告)日: 2005-02-24
- 发明人: Craig Cantrell , Marc Willebeek-Lemair , Dennis Cox , John McHale , Brian Smith , Donovan Kolbly
- 申请人: Craig Cantrell , Marc Willebeek-Lemair , Dennis Cox , John McHale , Brian Smith , Donovan Kolbly
- 主分类号: H04L12/26
- IPC分类号: H04L12/26 ; H04L29/06 ; H04L9/00
摘要:
An active network defense system is provided that is operable to monitor and block traffic in an automated fashion. This active network defense system is placed in-line with respect to the packet traffic data flow as a part of the network infrastructure. In this configuration, inspection and manipulation of every passing packet is possible. An algorithmic filtering operation applies statistical threshold filtering to the data flow in order to identify threats existing across multiple sessions. A trigger filtering operation applies header and content match filtering to the data flow in order to identify threats existing within individual sessions. Threatening packet traffic is blocked and threatening sessions are terminated. Suspicious traffic is extracted from the data flow for further examination with more comprehensive content matching as well as asset risk analysis. A flow control mechanism is provided to control passage rate for packets passing through the data flow.
公开/授权文献
- US07451489B2 Active network defense system and method 公开/授权日:2008-11-11
信息查询