Apparatus and method of detecting network attack situation

    公开(公告)号:US20060119486A1

    公开(公告)日:2006-06-08

    申请号:US11081682

    申请日:2005-03-17

    IPC分类号: G08B5/22

    摘要: Provided is an apparatus for detecting a network attack situation. The apparatus includes an alarm receiver receiving a plurality of alarms raised in a network to which the alarm receiver is connected, converting the alarms into predetermined alarm data, and outputting the alarm data; an alarm processor analyzing an attack situation in the network based on attributes of the alarm data and a number of times that the alarm data is generated; a memory storing basic data needed to analyze the state of the network and providing the basic data to the alarm processor; and an interface transmitting the result of the analysis by the alarm processor to an external device, receiving a predetermined critical value from the external device, which is a basis for determining the occurrence of the attack situation, and outputting the critical value to the alarm processor such that the alarm processor can store the critical value in the memory. Equal numbers of hash engines and detection engines for processing the alarms in the network to the number of data groups classified as network attack situations are formed in a line. Therefore, a network attack situation can be detected in real time based on a great number of alarms indicating intrusion detection.

    Network status display device and method using traffic flow-radar
    2.
    发明申请
    Network status display device and method using traffic flow-radar 有权
    网络状态显示装置及方法采用交通流雷达

    公开(公告)号:US20070206498A1

    公开(公告)日:2007-09-06

    申请号:US11599909

    申请日:2006-11-15

    IPC分类号: H04L12/26

    摘要: A network status display device using a traffic flow-radar is provided. The network status display device includes: a traffic feature extractor calculating flow occupancy rates for total flows, micro-flows and macro-flows with respect to each of a plurality of traffic features with reference to traffic information for each traffic feature such as a network address, a port, a transmitting/receiving host address or a protocol collected by an external traffic information collector, and storing the calculation result; a traffic status display unit displaying the flow occupancy rates for each traffic feature calculated and stored in the traffic feature extractor on a radar with dots for each traffic feature; and a traffic anomaly determination unit determining whether a network status is abnormal with reference to the radar for each traffic feature, detecting and reporting the type of the abnormal network status and harmful or abnormal traffic that generates the abnormal network status, when the abnormal status occurs.

    摘要翻译: 提供了使用交通流量雷达的网络状态显示装置。 网络状态显示装置包括:业务特征提取器,参考每个业务特征(例如网络地址)的业务信息来计算关于多个业务特征中的每一个的总流量,微流量和宏流量的流量占用率 ,端口,发送/接收主机地址或由外部交通信息收集器收集的协议,并存储计算结果; 交通状态显示单元,其显示针对每个交通特征点的雷达上计算并存储在交通特征提取器中的每个交通特征的流量占用率; 以及交通异常判定单元,针对每个流量特征,参照雷达确定网络状态是否异常,检测和报告异常网络状态的类型以及产生异常网络状态的有害或异常流量,当发生异常状态时 。

    Network status display device and method using traffic pattern map
    3.
    发明申请
    Network status display device and method using traffic pattern map 有权
    网络状态显示设备和使用流量模式图的方法

    公开(公告)号:US20070074288A1

    公开(公告)日:2007-03-29

    申请号:US11527850

    申请日:2006-09-26

    IPC分类号: G06F12/14

    摘要: A network status display device using a traffic pattern map is provided. The device includes: a traffic feature extractor extracting a port number of a port having the maximum occupancy of micro-flows and macro-flows for each network address section and host address section with reference to traffic information collected by an external traffic information collector, calculating and storing an occupancy rate of the port; a traffic status display unit making a network traffic pattern map expressed by destination-source network addresses and a host traffic pattern map expressed by destination-source host addresses and displaying the port information stored in the traffic feature extractor on the network traffic pattern map and the host traffic pattern map; and a traffic anomaly determination unit determining whether a network status is abnormal with reference to the network traffic pattern map and the host traffic pattern map and detecting and reporting a harmful or abnormal traffic which causes the abnormal network status. The device can determine whether the anomaly deteriorating the network performance exists and can easily and quickly detect the harmful or abnormal traffic which causes the anomaly by the use of the port information of the port having the maximum occupancy of the micro-flows and the macro-flows for each network address section and each host address section.

    摘要翻译: 提供了使用业务模式图的网络状态显示设备。 该设备包括:流量特征提取器,参考由外部交通信息收集器收集的交通信息,提取每个网络地址部分和主机地址部分具有最大占用微流量和宏流量的端口的端口号,计算 并存储所述端口的占用率; 形成由目的地源网络地址表示的网络流量模式图的流量状态显示单元和由目的地 - 源主机地址表示的主机流量模式图,并且在网络流量模式图上显示存储在流量特征提取器中的端口信息,并且 主机流量模式图; 以及流量异常判定单元,基于网络流量模式图和主机流量模式图来判断网络状态是否异常,并检测并报告导致异常网络状态的有害或异常流量。 该设备可以确定异常是否存在网络性能恶化,并可以通过使用具有微流量最大占用端口的端口信息和宏观流量来轻松快速地检测导致异常的有害或异常流量, 每个网络地址部分和每个主机地址部分的流程。

    Method of analyzing network attack situation
    4.
    发明申请
    Method of analyzing network attack situation 审中-公开
    分析网络攻击情况的方法

    公开(公告)号:US20050138425A1

    公开(公告)日:2005-06-23

    申请号:US10938113

    申请日:2004-09-10

    IPC分类号: H04L12/24 H04L9/00 H04L29/06

    CPC分类号: H04L63/1408 H04L63/1441

    摘要: Provided is a method for analyzing a network attack situation. The method categorizes network intrusion detection alerts into network attack situations, counts the frequency of same-featured intrusion alert occurrence for each network attack situation using a counting algorithm based on time slots, and analyzes the network attack situation based on the frequency of same-featured intrusion detection alert occurrence, the rate of same-featured intrusion detection alert occurrence, or an AND/OR combination of them. The network attack situation can be correctly detected in real time without relatively being influenced by the size of the network or amount of the occurrence of the intrusion detection alerts.

    摘要翻译: 提供了一种分析网络攻击情况的方法。 该方法将网络入侵检测警报分为网络攻击情况,使用基于时隙的计数算法对每个网络攻击情况的同一入侵警报发生频率进行计数,并根据相同频率的频率分析网络攻击情况 入侵检测警报发生,同一特征入侵检测警报发生率,或其AND / OR组合。 可以实时正确检测网络攻击情况,而不会受到网络规模或入侵检测警报发生量的影响。

    Apparatus and method for detecting network traffic abnormality
    6.
    发明申请
    Apparatus and method for detecting network traffic abnormality 审中-公开
    网络流量异常检测装置及方法

    公开(公告)号:US20060067240A1

    公开(公告)日:2006-03-30

    申请号:US11082031

    申请日:2005-03-15

    IPC分类号: G06F11/00

    摘要: An apparatus for detecting a network traffic abnormality includes: a pre-processing unit pre-processing traffics collected from at least one traffic collecting point in a network; a profiler modeling a normal traffic according to a characteristic of the traffic; an analysis model unit generating the thresholds based on the traffic; and an analyzer comparing a relative ratio of the traffic to the entire network traffics and the threshold and determining whether the traffic is abnormal. A combinational use of analysis methods using the relative ratio to the entire traffics and the absolute traffic volume takes into consideration of characteristics of a relative traffic ratio and absolute traffic volume, thereby providing a more reliable determination on whether the traffic is abnormal.

    摘要翻译: 一种用于检测网络流量异常的装置包括:预处理单元预处理从网络中的至少一个业务收集点收集的流量; 根据业务的特征对仿真流量进行建模的分析器; 分析模型单元,基于所述流量生成所述阈值; 以及比较流量与整个网络流量的相对比率和阈值并确定流量是否异常的分析器。 使用与整个业务相对比率和绝对业务量的分析方法的组合使用考虑了相对业务量比和绝对业务量的特性,从而为流量是否异常提供了更可靠的决定。

    Apparatus for SCORM-based e-learning contents service in digital broadcasting system and method thereof
    7.
    发明申请
    Apparatus for SCORM-based e-learning contents service in digital broadcasting system and method thereof 审中-公开
    数字广播系统中基于SCORM的电子学习内容服务的装置及其方法

    公开(公告)号:US20060136974A1

    公开(公告)日:2006-06-22

    申请号:US11122073

    申请日:2005-05-05

    IPC分类号: H04N7/173 H04N7/16

    摘要: An apparatus for a SCORM-based e-learning contents service in a digital broadcasting system and a method thereof that makes it possible to implement a SCORM-based e-learning method that is a PC-based leaning method currently recognized as the standard of the e-learning industries in an MPEG-2-based digital broadcasting system. The apparatus includes a set top box for transmitting information about a kind of terminal through a return channel and then reproducing a learning TS received through a broadcasting network on a digital television (TV) receiver in accordance with received XML sync information if a user is authenticated, a learning management system for transmitting an API adaptor supportable in the set top box through the return channel in accordance with the terminal kind information transmitted from the set top box, and a digital TV transmitter for generating the learning TS by packaging learning moving-picture data, learning data and sequencing information transmitted from the learning management system, generating the XML sync information, and transmitting the learning TS and the XML sync information through the broadcasting network.

    摘要翻译: 一种用于数字广播系统中基于SCORM的电子学习内容服务的装置及其方法,其可以实现基于SCORM的电子学习方法,该方法是基于PC的倾斜方法,该方法目前被认可为 基于MPEG-2的数字广播系统中的电子学习行业。 该装置包括:机顶盒,用于通过返回信道发送关于一种终端的信息,然后根据接收到的XML同步信息,如果用户被认证,则在数字电视(TV)接收机上再现通过广播网络接收的学习TS ,用于根据从机顶盒发送的终端种类信息通过返回信道发送可在机顶盒中支持的API适配器的学习管理系统;以及数字电视发射机,用于通过包装学习运动图像来生成学习TS 从学习管理系统发送的数据,学习数据和排序信息,生成XML同步信息,以及通过广播网络发送学习TS和XML同步信息。

    Thin film transistor array substrate and fabricating method thereof
    8.
    发明申请
    Thin film transistor array substrate and fabricating method thereof 有权
    薄膜晶体管阵列基板及其制造方法

    公开(公告)号:US20050253978A1

    公开(公告)日:2005-11-17

    申请号:US11019946

    申请日:2004-12-23

    摘要: A thin film transistor array substrate includes a first conductive pattern group including a gate electrode of a thin film transistor and a gate line connected to the gate electrode; a semiconductor pattern defining a channel of the thin film transistor; a second conductive pattern group including source and drain electrodes of the thin film transistor and a data line crossing the gate line, a pixel area being defined by the data line crossing the gate line; a third conductive pattern group having a pixel electrode connected to the thin film transistor; and at least one dummy pattern disposed between at least one of the first to third conductive pattern groups and an adjacent one of the semiconductor patterns.

    摘要翻译: 薄膜晶体管阵列基板包括:第一导电图案组,其包括薄膜晶体管的栅电极和连接到栅电极的栅极线; 限定薄膜晶体管的沟道的半导体图案; 包括薄膜晶体管的源极和漏极的第二导电图案组和与栅极线交叉的数据线,像素区域由与栅极线交叉的数据线限定; 具有连接到薄膜晶体管的像素电极的第三导电图案组; 以及设置在所述第一至第三导电图案组中的至少一个与所述半导体图案中的相邻一个之间的至少一个虚设图案。

    Air conditioner
    9.
    发明申请
    Air conditioner 审中-公开
    冷气机

    公开(公告)号:US20070079628A1

    公开(公告)日:2007-04-12

    申请号:US11407032

    申请日:2006-04-20

    IPC分类号: F25D23/12 F25D17/06

    摘要: An air discharge apparatus usable with an air conditioner includes a body formed with a suction opening and a discharge opening, a blowing fan arranged in the body to circulate air, and a partition to separate a suction path defined between the suction opening and the blowing fan from a discharge path defined between the blowing fan and the discharge opening. The partition has a vortex-restraint portion, which protrudes into the discharge path to occupy a portion of a bottom region of the cross sectional area of the discharge path, thereby serving to prevent generation of a vortex of air in the discharge path.

    摘要翻译: 可用于空调的排气装置包括形成有吸入口和排出口的主体,布置在主体中以使空气循环的吹风扇和用于分离在吸入口和吹风扇之间限定的吸入路径的分隔件 从吹风扇和排出口之间限定的排出路径。 分隔壁具有涡流限制部,该旋转限制部突出到排出路径中以占据排出路径的横截面积的底部区域的一部分,从而用于防止排出路径中的空气涡流的产生。

    Light guide plate and liquid crystal display device having the same
    10.
    发明申请
    Light guide plate and liquid crystal display device having the same 有权
    导光板及具有该导光板的液晶显示装置

    公开(公告)号:US20080031006A1

    公开(公告)日:2008-02-07

    申请号:US11730802

    申请日:2007-04-04

    申请人: Hee Kim Jin Kim Jin Kim

    发明人: Hee Kim Jin Kim Jin Kim

    IPC分类号: F21V8/00

    摘要: A light guide plate and a liquid crystal display device having the same. The light guide plate is disposed upstream of a liquid crystal panel to refract light supplied through an edge thereof, toward the liquid crystal panel. In the light guide plate, a plate body is disposed at a side of a light source for supplying light when a supply voltage is applied. A plurality of pyramidal diffusing elements are arrayed in a predetermined pattern on a surface of the plate body. Each of the diffusing elements is rotated clockwise or counterclockwise about an axis extending through a vertex of the diffusing element perpendicularly to the surface of the plate body so that an edge of the diffusing element facing a reference line connecting a central point of the light source to a central point of the plate body is angled 10° to 35° about the reference line.

    摘要翻译: 导光板和具有该导光板的液晶显示装置。 导光板配置在液晶面板的上游侧,将通过其边缘供给的光折射到液晶面板。 在导光板中,当施加电源电压时,板体设置在用于供应光的光源的一侧。 多个金字塔形扩散元件以预定图案排列在板体的表面上。 每个扩散元件围绕延伸穿过漫射元件的顶点的轴线顺时针或逆时针旋转,垂直于板体的表面,使得漫射元件的边缘面向连接光源的中心点的参考线, 板体的中心点围绕参考线倾斜10°至35°。