发明申请
- 专利标题: System and method for detecting abnormal traffic based on early notification
- 专利标题(中): 基于早期通知检测异常流量的系统和方法
-
申请号: US11176237申请日: 2005-07-08
-
公开(公告)号: US20070011741A1公开(公告)日: 2007-01-11
- 发明人: Jean-Marc Robert , Francois Cosquer
- 申请人: Jean-Marc Robert , Francois Cosquer
- 申请人地址: FR Paris
- 专利权人: ALCATEL
- 当前专利权人: ALCATEL
- 当前专利权人地址: FR Paris
- 主分类号: G06F12/14
- IPC分类号: G06F12/14 ; G06F11/00 ; G06F12/16 ; G06F15/18 ; G08B23/00
摘要:
This method and system for detecting abnormal traffic in a communications network is based on classifying the traffic in risk and status categories and maintaining a service status table with this information for each service at a respective node. The risk categories are initially established based on known software vulnerabilities recognized for the respective service. An early notifier enables further processing of services suspected of malware propagation. Status categories enable segregating the traffic with a “under attack status” from the “non under attack” status, so that the intrusion detection system at the respective node only processes the “under attack” traffic. In this way, the time and amount of processing performed by the intrusion detection system is considerably reduced.
公开/授权文献
信息查询