Patent · US Active

System and method for near-real time network attack detection, and system and method for unified detection via detection routing

US8677486B2 · kind B2 · utility

9Cited by
119References
24Claims
0Family size

Assignee

Inventors

Key dates

Filing dateApr 14, 2011
Grant dateMar 18, 2014
Priority date
Expiry dateDec 25, 2031

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L63/1408
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

A system includes a processor. The processor is configured to receive network traffic that includes a data block. The processor will generate a unique identifier (UID) for the file that includes a hash value corresponding to the file. The processor will determine whether the file is indicated as good or bad with the previously-stored UID. The processor will call a file-type specific detection nugget corresponding to the file's file-type to perform a full file inspection to detect whether the file is good or bad and store a result of the inspection together with the UID of the file, when the file is determined to be not listed in the previously-stored UIDs. The processor will not call the file-type specific detection nugget when the file's indicator is “good” or “bad” in the previously-stored UIDs. The processor will issue an alert about the bad file when the file's indicator is “bad”.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.