Invention Grant
US07936682B2 Detecting malicious attacks using network behavior and header analysis
有权
使用网络行为和标题分析来检测恶意攻击
- Patent Title: Detecting malicious attacks using network behavior and header analysis
- Patent Title (中): 使用网络行为和标题分析来检测恶意攻击
-
Application No.: US11271133Application Date: 2005-11-09
-
Publication No.: US07936682B2Publication Date: 2011-05-03
- Inventor: Sumeet Singh , George Varghese
- Applicant: Sumeet Singh , George Varghese
- Applicant Address: US CA San Jose
- Assignee: Cisco Technology, Inc.
- Current Assignee: Cisco Technology, Inc.
- Current Assignee Address: US CA San Jose
- Agency: Schwegman, Lundberg & Woessner, P.A.
- Main IPC: H04L12/26
- IPC: H04L12/26

Abstract:
A method and apparatus for detecting malicious attacks is described. The method may comprise obtaining routing information from a packet communicated via a network and maintaining a count of packets associated with a device associated with the routing information. For example, the routing information may a source or destination IP address, a port number, or any other routing information. The device may be classified as a potentially malicious device when the count exceeds a threshold. The count may be incremented when the TCP SYN flag is set and the TCP ACK flag is not set. An embodiment comprises obtaining a source hash of the source IP address and a destination hash of the destination IP address. Thereafter, the source hash and the destination hash may be mapped to multi stage filters. The device associated with the packet may then be selectively categorizing as a suspicious device.
Public/Granted literature
- US20060098585A1 Detecting malicious attacks using network behavior and header analysis Public/Granted day:2006-05-11
Information query