METHOD AND APPARATUS FOR MONITORING AND PROCESSING DNS QUERY TRAFFIC
    1.
    发明申请
    METHOD AND APPARATUS FOR MONITORING AND PROCESSING DNS QUERY TRAFFIC 审中-公开
    用于监控和处理DNS查询业务的方法和设备

    公开(公告)号:US20120159623A1

    公开(公告)日:2012-06-21

    申请号:US13325981

    申请日:2011-12-14

    申请人: Yang-Seo CHOI

    发明人: Yang-Seo CHOI

    IPC分类号: G06F21/20 G06F15/16

    摘要: A method for monitoring and processing domain name system (DNS) query traffic includes: monitoring DNS query traffic in each time slot during a monitoring period comprised of n number of time slots; extracting traffic information during the monitoring period by using the DNS query traffic monitored in said each time slot; and analyzing the extracted traffic information to detect a DNS traffic flooding attack.

    摘要翻译: 一种用于监视和处理域名系统(DNS)查询流量的方法包括:在由n个时隙组成的监视期间内监视每个时隙中的DNS查询流量; 通过使用在所述每个时隙中监视的DNS查询流量在监视期间提取交通信息; 并分析所提取的流量信息以检测DNS流量洪泛攻击。

    SYSTEM AND METHOD FOR DETECTING FILE
    2.
    发明申请
    SYSTEM AND METHOD FOR DETECTING FILE 审中-公开
    检测文件的系统和方法

    公开(公告)号:US20080291912A1

    公开(公告)日:2008-11-27

    申请号:US12044410

    申请日:2008-03-07

    IPC分类号: H04L12/56

    CPC分类号: H04L69/22

    摘要: The present invention relates to a file detecting system and a method thereof. The file detecting system uses a signature of a file header and collects a network packet including a file to be detected among packets transmitted/received through a network. Subsequently, after the network protocol header is eliminated from the collected network packet, the file is reassembled and recovered. The recovered file is verified, and the verified file is transmitted to various file analysis systems.

    摘要翻译: 文件检测系统及其方法技术领域本发明涉及文件检测系统及其方法。 文件检测系统使用文件头的签名,并且通过网络收发包含要检测的文件的网络分组,所述网络分组包括发送/接收的分组。 随后,在从收集的网络分组中消除网络协议报头之后,重新组合并恢复该文件。 验证恢复的文件,并将验证的文件传输到各种文件分析系统。

    METHOD AND APPARATUS FOR PROTECTING APPLICATION LAYER IN COMPUTER NETWORK SYSTEM
    4.
    发明申请
    METHOD AND APPARATUS FOR PROTECTING APPLICATION LAYER IN COMPUTER NETWORK SYSTEM 有权
    用于保护计算机网络系统中应用层的方法和装置

    公开(公告)号:US20110016526A1

    公开(公告)日:2011-01-20

    申请号:US12643100

    申请日:2009-12-21

    IPC分类号: G06F15/16 G06F21/00

    摘要: A method and apparatus for protecting an application layer in a computer network system. The method includes creating a session between a client and a data provider in response to a session connection request from the client, and determining the client as an application layer attacking client when the client generates a session termination request before the data provider transmits to the client a response packet to a data request from the client under the created session.

    摘要翻译: 一种用于保护计算机网络系统中的应用层的方法和装置。 该方法包括响应于来自客户端的会话连接请求,在客户机和数据提供者之间创建会话,并且在数据提供者向客户端发送客户端之前,当客户机生成会话终止请求时,将客户端确定为攻击客户端的应用层 来自客户端在创建的会话下的数据请求的响应数据包。