首页> 外国专利> A METHOD AND A DEVICE FOR NETWORK-BASED INTERNET WORM DETECTION WITH THE VULNERABILITY ANALYSIS AND ATTACK MODELING

A METHOD AND A DEVICE FOR NETWORK-BASED INTERNET WORM DETECTION WITH THE VULNERABILITY ANALYSIS AND ATTACK MODELING

机译:具有漏洞分析和攻击建模的基于网络的互联网蠕虫检测方法和装置

摘要

A method and a device for detecting Internet worms based on the network by using vulnerability analysis and attack modeling are provided to efficiently detect and control the Internet worms determined as an attack packet before real attack by analyzing vulnerability of application programs and modeling the attacks. A vulnerability information storing part(150) stores vulnerability information, which is needed for detecting attack, of application programs. A risk determiner(120) determines whether the received packet is transmitted to a vulnerable application program. A packet contents extractor(140) extracts information needed for determining an attack packet from the packet transmitted to the vulnerable application program by using the vulnerability information. An attack determiner(170) determines the attack packet by comparing/analyzing the information extracted from the packet and the vulnerability information stored in the vulnerability storing part. A divided packet processor(130) integrates the information divided from the packet transmitted to the vulnerable application program or corrects order of the divided information before the information for the packet is output to the packet contents extractor.
机译:本发明提供了一种利用漏洞分析和攻击建模方法基于网络的互联网蠕虫检测方法和装置,通过对应用程序的漏洞进行建模和攻击建模,有效地检测和控制了被确定为实际攻击之前的攻击报文的互联网蠕虫。漏洞信息存储部分(150)存储检测应用程序攻击的漏洞信息。风险确定器(120)确定接收到的分组是否被发送到易受攻击的应用程序。分组内容提取器(140)通过使用脆弱性信息从发送给脆弱应用程序的分组中提取确定攻击分组所需的信息。攻击确定器(170)通过比较/分析从分组提取的信息和存储在漏洞存储部分中的漏洞信息来确定攻击分组。划分的分组处理器(130)将从发送给易受攻击的应用程序的分组中分离出的信息进行整合,或者在将分组的信息输出到分组内容提取器之前校正划分的信息的顺序。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号