Real-time network attack pattern detection system for unknown network attack and method thereof
US7571477B2 · kind B2 · utility
Assignee
Inventors
Key dates
| Filing date | Mar 24, 2005 |
| Grant date | Aug 4, 2009 |
| Priority date | — |
| Expiry date | Jul 25, 2027 |
Classification
- Technology area (CPC H)Electricity
- CPC primaryH04L63/1408
- WIPO fieldDigital communication
- WIPO sectorElectrical engineering
Abstract
In a real-time network attack pattern detection system and method, a common pattern is detected in real time from packets, which are suspected to be a network attack such as Worm, to effectively block the attack. The system includes: a suspicious packet detector for classifying a suspicious attack packet from all input packets; a first data delaying unit for receiving the input packet from the suspicious packet detector to output an one-clock delayed data; a second data delaying unit for receiving an output signal from the first data delaying unit to output an one-clock delayed data; a hash key generator for receiving an output data of the suspicious packet detector, an output data of the first data delaying unit and an output data of the second data delaying unit to generate a hash key; a hash table for storing a lookup result obtained by the hash key generated from the hash key generator; and an existence & hit checker for checking the lookup result of the hash table.
Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.