首页> 外国专利> A Method and a Device for Network-Based Internet Worm Detection With The Vulnerability Analysis and Attack Modeling

A Method and a Device for Network-Based Internet Worm Detection With The Vulnerability Analysis and Attack Modeling

机译:漏洞分析与攻击建模的基于网络的互联网蠕虫检测方法及装置

摘要

The present invention relates to a network (network) for the Internet worm (internet worm) detection devices and detection methods using the vulnerability analysis and attack system modeling (modeling), including the keyword that is used to attack a vulnerability of an application vulnerability store vulnerability to store vulnerability information required for the attack detection information unit, the network (network) packet (packet) to be transmitted on the determined presence threat to determine whether to be transmitted to the application having the vulnerability part, application having the vulnerability whether in the packet it is to be sent to the program packet information extracting unit, and the attack packets by comparing / analyzing the vulnerability information that is stored in the information and the vulnerability storage section extracted in the packet to extract information needed for breaking is determined by using the vulnerability information consists of a part to determine attacked judgment, whereby utilizing the vulnerability of the application and detects worms by modeling the type of attack and are able to prepare responses prior to generating the actual attack, divided or arrival, the order changed by storing only a portion of the information belonging to a particular session of a packet that can be used to secure the efficiency of the storage device and to reduce the resources required for packet processing. ; Internet worms, vulnerabilities, detect violations
机译:本发明涉及用于互联网蠕虫(internet worm)检测设备的网络(网络)和使用漏洞分析和攻击系统建模(modeling)的检测方法,包括用于攻击应用程序漏洞存储的漏洞的关键字漏洞存储攻击检测信息单元,确定的存在威胁时要传输的网络(网络)包(包)所需的漏洞信息,以确定是否要传输到具有漏洞部分的应用程序,具有漏洞的应用程序是否存在将该报文发送给程序包信息提取单元,通过比较/分析该信息中存储的漏洞信息和该报文中提取的漏洞存储部分,提取破坏所需的信息,确定攻击报文,使用漏洞信息包括确定受攻击的判断,从而利用应用程序的漏洞并通过对攻击类型进行建模来检测蠕虫,并能够在生成实际攻击,划分或到达之前准备响应,通过仅存储属于以下内容的信息的一部分来更改顺序数据包的特定会话,可用于确保存储设备的效率并减少数据包处理所需的资源。 ; Internet蠕虫,漏洞,检测违规

著录项

  • 公开/公告号KR100862187B1

    专利类型

  • 公开/公告日2008-10-09

    原文格式PDF

  • 申请/专利权人

    申请/专利号KR20060105179

  • 发明设计人 김대원;최양서;김익균;오진태;

    申请日2006-10-27

  • 分类号G06F11/00;

  • 国家 KR

  • 入库时间 2022-08-21 19:51:35

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号