发明申请
- 专利标题: Method of analyzing network attack situation
- 专利标题(中): 分析网络攻击情况的方法
-
申请号: US10938113申请日: 2004-09-10
-
公开(公告)号: US20050138425A1公开(公告)日: 2005-06-23
- 发明人: Jin Kim , Soo Lee , Dongyoung Kim , Beom Chang , Jung Na , Sung Sohn , Chee Park
- 申请人: Jin Kim , Soo Lee , Dongyoung Kim , Beom Chang , Jung Na , Sung Sohn , Chee Park
- 优先权: KR2003-93100 20031218
- 主分类号: H04L12/24
- IPC分类号: H04L12/24 ; H04L9/00 ; H04L29/06
摘要:
Provided is a method for analyzing a network attack situation. The method categorizes network intrusion detection alerts into network attack situations, counts the frequency of same-featured intrusion alert occurrence for each network attack situation using a counting algorithm based on time slots, and analyzes the network attack situation based on the frequency of same-featured intrusion detection alert occurrence, the rate of same-featured intrusion detection alert occurrence, or an AND/OR combination of them. The network attack situation can be correctly detected in real time without relatively being influenced by the size of the network or amount of the occurrence of the intrusion detection alerts.
信息查询