System and method for near-real time network attack detection, and system and method for unified detection via detection routing
US8677486B2 · kind B2 · utility
Assignee
Inventors
Key dates
| Filing date | Apr 14, 2011 |
| Grant date | Mar 18, 2014 |
| Priority date | — |
| Expiry date | Dec 25, 2031 |
Classification
- Technology area (CPC H)Electricity
- CPC primaryH04L63/1408
- WIPO fieldDigital communication
- WIPO sectorElectrical engineering
Abstract
A system includes a processor. The processor is configured to receive network traffic that includes a data block. The processor will generate a unique identifier (UID) for the file that includes a hash value corresponding to the file. The processor will determine whether the file is indicated as good or bad with the previously-stored UID. The processor will call a file-type specific detection nugget corresponding to the file's file-type to perform a full file inspection to detect whether the file is good or bad and store a result of the inspection together with the UID of the file, when the file is determined to be not listed in the previously-stored UIDs. The processor will not call the file-type specific detection nugget when the file's indicator is “good” or “bad” in the previously-stored UIDs. The processor will issue an alert about the bad file when the file's indicator is “bad”.
Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.