Invention Grant
- Patent Title: Methods and systems for automated detection and tracking of network attacks
- Patent Title (中): 自动检测和跟踪网络攻击的方法和系统
-
Application No.: US12195359Application Date: 2008-08-20
-
Publication No.: US08726382B2Publication Date: 2014-05-13
- Inventor: Stephen Knapp , Timothy Mark Aldrich
- Applicant: Stephen Knapp , Timothy Mark Aldrich
- Applicant Address: US IL Chicago
- Assignee: The Boeing Company
- Current Assignee: The Boeing Company
- Current Assignee Address: US IL Chicago
- Agency: Armstrong Teasdale LLP
- Main IPC: G06F12/14
- IPC: G06F12/14 ; G06F17/00 ; H04L29/06 ; H04L9/32

Abstract:
Methods for tracking attacking nodes are described and include extracting, from a database, an instance of each unique packet header associated with IP-to-IP packets transmitted over a time period. The method includes determining from extracted headers, which nodes have attempted to establish a connection with an excessive number of other nodes over a period, identifying these as potential attacking nodes, determining from the headers, which other nodes responded with a TCP SYN/ACK packet indicating a willingness to establish connections, and a potential for compromise. Nodes scanned by potential attacking nodes are disqualified from the identified nodes based on at least one of: data in the headers relating to at least one of an amount of data transferred, and scanning activities conducted by the nodes that responded to a potential attacking node with a TCP SYN/ACK packet. Any remaining potential attacking nodes and scanned nodes are presented to a user.
Public/Granted literature
- US20100050262A1 METHODS AND SYSTEMS FOR AUTOMATED DETECTION AND TRACKING OF NETWORK ATTACKS Public/Granted day:2010-02-25
Information query