发明授权
- 专利标题: Applying blocking measures progressively to malicious network traffic
- 专利标题(中): 对恶意网络流量逐步应用阻塞措施
-
申请号: US10442008申请日: 2003-05-20
-
公开(公告)号: US07308716B2公开(公告)日: 2007-12-11
- 发明人: Robert William Danford , Kenneth M. Farmer , Clark Debs Jeffries , Robert B. Sisk , Michael A. Walter
- 申请人: Robert William Danford , Kenneth M. Farmer , Clark Debs Jeffries , Robert B. Sisk , Michael A. Walter
- 申请人地址: US NY Armonk
- 专利权人: International Business Machines Corporation
- 当前专利权人: International Business Machines Corporation
- 当前专利权人地址: US NY Armonk
- 代理机构: Schmeiser, Olsen & Watts
- 代理商 David R. Irvin; John R. Pivnichny
- 主分类号: G06F15/08
- IPC分类号: G06F15/08 ; G08B23/00
摘要:
A method of progressive response for invoking and suspending blocking measures that defend against network anomalies such as malicious network traffic so that false positives and false negatives are minimized. When an anomaly is detected, the detector notifies protective equipment such as a firewall or a router to invoke a blocking measure. The blocking measure is maintained for an initial duration, after which it is suspended while another test for the anomaly is made. If the anomaly is no longer evident, the method returns to the state of readiness. Otherwise, a loop is executed to re-applying the blocking measure for a specified duration, then suspend the blocking measure and test again for the anomaly. If the anomaly is detected, the blocking measure is re-applied, and its duration is adapted. If the anomaly is no longer detected, the method returns to the state of readiness.
公开/授权文献
信息查询