MALICIOUS NETWORK TRAFFIC IDENTIFICATION
    4.
    发明申请

    公开(公告)号:US20190207955A1

    公开(公告)日:2019-07-04

    申请号:US16065603

    申请日:2016-12-22

    IPC分类号: H04L29/06

    摘要: A method for identifying malicious network traffic communicated via a computer network, the method including: evaluating a measure of a correlation fractal dimension for a portion of network traffic over a monitored network connection; comparing the measure of correlation fractal dimension with a reference measure of correlation fractal dimension for a corresponding portion of network traffic of a malicious network connection so as to determine if malicious network traffic is communicated over the monitored network connection.

    INTEGRATED NETWORK INTRUSION DETECTION
    9.
    发明申请

    公开(公告)号:US20190124095A1

    公开(公告)日:2019-04-25

    申请号:US15982318

    申请日:2018-05-17

    申请人: Intel Corporation

    发明人: Satyendra Yadav

    IPC分类号: H04L29/06

    摘要: Intrusion preludes may be detected (including detection using fabricated responses to blocked network requests), and particular sources of network communications may be singled out for greater scrutiny, by performing intrusion analysis on packets blocked by a firewall. An integrated intrusion detection system uses an end-node firewall that is dynamically controlled using invoked-application information and a network policy. The system may use various alert levels to trigger heightened monitoring states, alerts sent to a security operation center, and/or logging of network activity for later forensic analysis. The system may monitor network traffic to block traffic that violates the network policy, monitor blocked traffic to detect an intrusion prelude, and monitor traffic from a potential intruder when an intrusion prelude is detected. The system also may track behavior of applications using the network policy to identify abnormal application behavior, and monitor traffic from an abnormally behaving application to identify an intrusion.