发明申请
US20170034195A1 APPARATUS AND METHOD FOR DETECTING ABNORMAL CONNECTION BEHAVIOR BASED ON ANALYSIS OF NETWORK DATA
审中-公开
基于网络数据分析检测异常连接行为的装置和方法
- 专利标题: APPARATUS AND METHOD FOR DETECTING ABNORMAL CONNECTION BEHAVIOR BASED ON ANALYSIS OF NETWORK DATA
- 专利标题(中): 基于网络数据分析检测异常连接行为的装置和方法
-
申请号: US15004412申请日: 2016-01-22
-
公开(公告)号: US20170034195A1公开(公告)日: 2017-02-02
- 发明人: Jong-Hoon LEE , Ik-Kyun KIM
- 申请人: ELECTRONICS AND TELECOMMUNICATIONS RESEARCH INSTITUTE
- 优先权: KR10-2015-0105866 20150727
- 主分类号: H04L29/06
- IPC分类号: H04L29/06
摘要:
An apparatus and method for detecting abnormal connection behavior are disclosed. The apparatus for detecting abnormal connection behavior includes a data extraction unit, a data storage unit, and a detection unit. The data extraction unit collects network data transmitted and received over a network including a plurality of hosts, and extracts data required for the detection of abnormal connection behavior from the network data. The data storage unit stores the extracted data required for the detection of abnormal connection behavior. The detection unit detects abnormal connection behavior based on characteristic factors corresponding to the stored data required for the detection of abnormal connection behavior and characteristic factors corresponding to malicious behavior.
信息查询