发明申请
- 专利标题: APPARATUS AND METHOD OF DETECTING NETWORK ATTACK SITUATION
- 专利标题(中): 检测网络攻击状况的装置和方法
-
申请号: US12275906申请日: 2008-11-21
-
公开(公告)号: US20090094699A1公开(公告)日: 2009-04-09
- 发明人: Jin Oh KIM , Seon Gyoung Sohn , Hyochan Bang , Soo Hyung Lee , Dongyoung Kim , Beom Hwan Chang , Geon Lyang Kim , Hyun Joo Kim , Jung Chan Na , Jong Soo Jang , Sung Won Sohn
- 申请人: Jin Oh KIM , Seon Gyoung Sohn , Hyochan Bang , Soo Hyung Lee , Dongyoung Kim , Beom Hwan Chang , Geon Lyang Kim , Hyun Joo Kim , Jung Chan Na , Jong Soo Jang , Sung Won Sohn
- 申请人地址: KR Daejeon-city
- 专利权人: Electronics and Telecommunications Research Institute
- 当前专利权人: Electronics and Telecommunications Research Institute
- 当前专利权人地址: KR Daejeon-city
- 优先权: KR10-2004-0101086 20041203
- 主分类号: G06F15/18
- IPC分类号: G06F15/18 ; G08B23/00
摘要:
Provided is an apparatus for detecting a network attack situation. The apparatus includes an alarm receiver receiving a plurality of alarms raised in a network to which the alarm receiver is connected, converting the alarms into predetermined alarm data, and outputting the alarm data; an alarm processor analyzing an attack situation in the network based on attributes of the alarm data and a number of times that the alarm data is generated; a memory storing basic data needed to analyze the state of the network and providing the basic data to the alarm processor; and an interface transmitting the result of the analysis by the alarm processor to an external device, receiving a predetermined critical value from the external device, which is a basis for determining the occurrence of the attack situation, and outputting the critical value to the alarm processor such that the alarm processor can store the critical value in the memory. Equal numbers of hash engines and detection engines for processing the alarms in the network to the number of data groups classified as network attack situations are formed in a line. Therefore, a network attack situation can be detected in real time based on a great number of alarms indicating intrusion detection.
信息查询