摘要:
Provided is an apparatus for detecting a network attack situation. The apparatus includes an alarm receiver receiving a plurality of alarms raised in a network to which the alarm receiver is connected, converting the alarms into predetermined alarm data, and outputting the alarm data; an alarm processor analyzing an attack situation in the network based on attributes of the alarm data and a number of times that the alarm data is generated; a memory storing basic data needed to analyze the state of the network and providing the basic data to the alarm processor; and an interface transmitting the result of the analysis by the alarm processor to an external device, receiving a predetermined critical value from the external device, which is a basis for determining the occurrence of the attack situation, and outputting the critical value to the alarm processor such that the alarm processor can store the critical value in the memory. Equal numbers of hash engines and detection engines for processing the alarms in the network to the number of data groups classified as network attack situations are formed in a line. Therefore, a network attack situation can be detected in real time based on a great number of alarms indicating intrusion detection.
摘要:
A network status display device using a traffic flow-radar is provided. The network status display device includes: a traffic feature extractor calculating flow occupancy rates for total flows, micro-flows and macro-flows with respect to each of a plurality of traffic features with reference to traffic information for each traffic feature such as a network address, a port, a transmitting/receiving host address or a protocol collected by an external traffic information collector, and storing the calculation result; a traffic status display unit displaying the flow occupancy rates for each traffic feature calculated and stored in the traffic feature extractor on a radar with dots for each traffic feature; and a traffic anomaly determination unit determining whether a network status is abnormal with reference to the radar for each traffic feature, detecting and reporting the type of the abnormal network status and harmful or abnormal traffic that generates the abnormal network status, when the abnormal status occurs.
摘要:
A network status display device using a traffic pattern map is provided. The device includes: a traffic feature extractor extracting a port number of a port having the maximum occupancy of micro-flows and macro-flows for each network address section and host address section with reference to traffic information collected by an external traffic information collector, calculating and storing an occupancy rate of the port; a traffic status display unit making a network traffic pattern map expressed by destination-source network addresses and a host traffic pattern map expressed by destination-source host addresses and displaying the port information stored in the traffic feature extractor on the network traffic pattern map and the host traffic pattern map; and a traffic anomaly determination unit determining whether a network status is abnormal with reference to the network traffic pattern map and the host traffic pattern map and detecting and reporting a harmful or abnormal traffic which causes the abnormal network status. The device can determine whether the anomaly deteriorating the network performance exists and can easily and quickly detect the harmful or abnormal traffic which causes the anomaly by the use of the port information of the port having the maximum occupancy of the micro-flows and the macro-flows for each network address section and each host address section.
摘要:
Provided is a method for analyzing a network attack situation. The method categorizes network intrusion detection alerts into network attack situations, counts the frequency of same-featured intrusion alert occurrence for each network attack situation using a counting algorithm based on time slots, and analyzes the network attack situation based on the frequency of same-featured intrusion detection alert occurrence, the rate of same-featured intrusion detection alert occurrence, or an AND/OR combination of them. The network attack situation can be correctly detected in real time without relatively being influenced by the size of the network or amount of the occurrence of the intrusion detection alerts.
摘要:
Provided is an apparatus for detecting and visualizing anomalies in network traffic which includes a traffic information storing portion storing information on network traffic, a traffic state display portion presenting a status of the network traffic generated for a predetermined threshold time based on the information on network traffic on an orthogonal coordinates system in a form of a graph connecting at least one point data as a coordinate value, and a traffic anomalies determination portion determining an existence of anomalies in the network traffic based on a shape of the graph.
摘要:
An apparatus for detecting a network traffic abnormality includes: a pre-processing unit pre-processing traffics collected from at least one traffic collecting point in a network; a profiler modeling a normal traffic according to a characteristic of the traffic; an analysis model unit generating the thresholds based on the traffic; and an analyzer comparing a relative ratio of the traffic to the entire network traffics and the threshold and determining whether the traffic is abnormal. A combinational use of analysis methods using the relative ratio to the entire traffics and the absolute traffic volume takes into consideration of characteristics of a relative traffic ratio and absolute traffic volume, thereby providing a more reliable determination on whether the traffic is abnormal.
摘要:
An apparatus for a SCORM-based e-learning contents service in a digital broadcasting system and a method thereof that makes it possible to implement a SCORM-based e-learning method that is a PC-based leaning method currently recognized as the standard of the e-learning industries in an MPEG-2-based digital broadcasting system. The apparatus includes a set top box for transmitting information about a kind of terminal through a return channel and then reproducing a learning TS received through a broadcasting network on a digital television (TV) receiver in accordance with received XML sync information if a user is authenticated, a learning management system for transmitting an API adaptor supportable in the set top box through the return channel in accordance with the terminal kind information transmitted from the set top box, and a digital TV transmitter for generating the learning TS by packaging learning moving-picture data, learning data and sequencing information transmitted from the learning management system, generating the XML sync information, and transmitting the learning TS and the XML sync information through the broadcasting network.
摘要:
A thin film transistor array substrate includes a first conductive pattern group including a gate electrode of a thin film transistor and a gate line connected to the gate electrode; a semiconductor pattern defining a channel of the thin film transistor; a second conductive pattern group including source and drain electrodes of the thin film transistor and a data line crossing the gate line, a pixel area being defined by the data line crossing the gate line; a third conductive pattern group having a pixel electrode connected to the thin film transistor; and at least one dummy pattern disposed between at least one of the first to third conductive pattern groups and an adjacent one of the semiconductor patterns.
摘要:
An air discharge apparatus usable with an air conditioner includes a body formed with a suction opening and a discharge opening, a blowing fan arranged in the body to circulate air, and a partition to separate a suction path defined between the suction opening and the blowing fan from a discharge path defined between the blowing fan and the discharge opening. The partition has a vortex-restraint portion, which protrudes into the discharge path to occupy a portion of a bottom region of the cross sectional area of the discharge path, thereby serving to prevent generation of a vortex of air in the discharge path.
摘要:
A light guide plate and a liquid crystal display device having the same. The light guide plate is disposed upstream of a liquid crystal panel to refract light supplied through an edge thereof, toward the liquid crystal panel. In the light guide plate, a plate body is disposed at a side of a light source for supplying light when a supply voltage is applied. A plurality of pyramidal diffusing elements are arrayed in a predetermined pattern on a surface of the plate body. Each of the diffusing elements is rotated clockwise or counterclockwise about an axis extending through a vertex of the diffusing element perpendicularly to the surface of the plate body so that an edge of the diffusing element facing a reference line connecting a central point of the light source to a central point of the plate body is angled 10° to 35° about the reference line.