首页> 外国专利> Network defense system and framework for detecting and geolocating botnet cyber attacks

Network defense system and framework for detecting and geolocating botnet cyber attacks

机译:用于检测和定位僵尸网络网络攻击的网络防御系统和框架

摘要

A network defense system is described that provides network sensor infrastructure and a framework for managing and executing advanced cyber security algorithms specialized for detecting highly-distributed, stealth network attacks. In one example, a system includes a data collection and storage subsystem that provides a central repository to store network traffic data received from sensors positioned within geographically separate networks. Cyber defense algorithms analyze the network traffic data and detect centrally-controlled malware that is configured to perform distributed network attacks (“botnet attacks”) from devices within the geographically separate networks. A visualization and decision-making subsystem generates a user interface that presents an electronic map of geographic locations of source devices and target devices of the botnet attacks. The data collection and storage subsystem stores a manifest of parameters for the network traffic data to be analyzed by each of the cyber defense algorithms.
机译:描述了一种网络防御系统,该网络防御系统提供了网络传感器基础结构以及用于管理和执行专门用于检测高度分布的隐形网络攻击的高级网络安全算法的框架。在一个示例中,一种系统包括数据收集和存储子系统,该数据收集和存储子系统提供中央存储库以存储从定位在地理上分离的网络内的传感器接收的网络业务数据。网络防御算法分析网络流量数据并检测集中控制的恶意软件,该恶意软件被配置为从地理位置独立的网络内的设备执行分布式网络攻击(“僵尸网络攻击”)。可视化和决策子系统可生成用户界面,该界面呈现僵尸网络攻击源设备和目标设备地理位置的电子地图。数据收集和存储子系统存储用于每个网络防御算法要分析的网络流量数据的参数清单。

著录项

  • 公开/公告号US9083741B2

    专利类型

  • 公开/公告日2015-07-14

    原文格式PDF

  • 申请/专利权人 ARCHITECTURE TECHNOLOGY CORPORATION;

    申请/专利号US201213730706

  • 发明设计人 JUDSON POWERS;

    申请日2012-12-28

  • 分类号H04L29/06;

  • 国家 US

  • 入库时间 2022-08-21 15:20:41

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号