Invention Grant
- Patent Title: Method and apparatus for detecting network attacks and generating attack signatures based on signature merging
-
Application No.: US15225560Application Date: 2016-08-01
-
Publication No.: US10225269B2Publication Date: 2019-03-05
- Inventor: Sungwon Yi
- Applicant: ELECTRONICS AND TELECOMMUNICATIONS RESEARCH INSTITUTE
- Applicant Address: KR Daejeon
- Assignee: ELECTRONICS AND TELECOMMUNICATIONS RESEARCH INSTITUTE
- Current Assignee: ELECTRONICS AND TELECOMMUNICATIONS RESEARCH INSTITUTE
- Current Assignee Address: KR Daejeon
- Priority: KR10-2015-0160625 20151116
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06F17/30

Abstract:
There are provided a method and an apparatus for detecting attacks and automatically generating attack signatures based on signature merging. A method for detecting attacks and automatically generating attack signatures based on signature merging includes detecting a character string matched to at least one previously stored compressed attack signature in an input packet received from a network, determining whether the character string detected in the primary attack detection is matched to at least one previously stored individual attack signature, and, if the detected character string is matched to the at least one previously stored individual attack signature, determining the input packet as an attack packet, and, if the detected character string is not matched, determining the input packet as a new attack signature.
Public/Granted literature
Information query