Invention Grant
- Patent Title: Suspicious packet detection device and suspicious packet detection method thereof
-
Application No.: US16202084Application Date: 2018-11-27
-
Publication No.: US11057403B2Publication Date: 2021-07-06
- Inventor: Chi-Kuan Chiu , Hsiao-Hsien Chang , Te-En Wei
- Applicant: Institute For Information Industry
- Applicant Address: TW Taipei
- Assignee: Institute For Information Industry
- Current Assignee: Institute For Information Industry
- Current Assignee Address: TW Taipei
- Agency: Skaar Ulbrich Macari, P.A.
- Priority: TW107138823 20181101
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06F16/955 ; G06K9/62 ; G06N20/00 ; G06F16/906

Abstract:
A suspicious packet detection device and a suspicious packet detection method thereof are provided. The suspicious packet detection device captures an HTTP packet transmitted from an internal network to an external network, and based on an HTTP header of the HTTP packet, determines that the HTTP packet belongs to one of a browser category and an application category and identifies the HTTP packet as one of a normal packet and a suspicious packet. When the HTTP packet is identified as the normal packet, the suspicious packet detection device further verifies whether the HTTP packet is the suspicious packet or not by comparing the HTTP header with relevance information or by using a URL classification model.
Information query