Invention Grant
US07865955B2 Apparatus and method for extracting signature candidates of attacking packets
失效
用于提取攻击包的签名候选者的装置和方法
- Patent Title: Apparatus and method for extracting signature candidates of attacking packets
- Patent Title (中): 用于提取攻击包的签名候选者的装置和方法
-
Application No.: US11924100Application Date: 2007-10-25
-
Publication No.: US07865955B2Publication Date: 2011-01-04
- Inventor: Hwa Shin Moon , Sung Won Yi , Jin Tae Oh
- Applicant: Hwa Shin Moon , Sung Won Yi , Jin Tae Oh
- Applicant Address: KR Daejeon
- Assignee: Electronics and Telecommunications Research Institute
- Current Assignee: Electronics and Telecommunications Research Institute
- Current Assignee Address: KR Daejeon
- Agency: Ladas & Parry LLP
- Priority: KR10-2006-0115960 20061122
- Main IPC: G06F11/00
- IPC: G06F11/00 ; G06F12/14 ; H04L9/00

Abstract:
An apparatus and method for extracting signature candidates and optimizing a corresponding signature are provided. The apparatus includes a packet separator, a header parser, a traffic information generator, a substring extractor, and a signature candidate extractor. The packet separator separates a packet into a header and a payload. The header information parser parses the header information, and the traffic information generator generates traffic information. The substring extractor measures a frequency of appearing of a substring with a predetermined length in the separated payload for a constant observation period, and extracts a substring having a frequency higher than a predetermined setup value by updating the measured frequency information to a substring frequency table. The signature candidate extractor generates a signature by collecting the extracted substring information and the generated traffic information, updates a signature frequency table, and extracts a signature candidate with reference to information of the signature frequency table.
Public/Granted literature
- US20080120721A1 APPARATUS AND METHOD FOR EXTRACTING SIGNATURE CANDIDATES OF ATTACKING PACKETS Public/Granted day:2008-05-22
Information query