CA2600517A1 - Network attack detection - Google Patents

Network attack detection Download PDF

Info

Publication number
CA2600517A1
CA2600517A1 CA002600517A CA2600517A CA2600517A1 CA 2600517 A1 CA2600517 A1 CA 2600517A1 CA 002600517 A CA002600517 A CA 002600517A CA 2600517 A CA2600517 A CA 2600517A CA 2600517 A1 CA2600517 A1 CA 2600517A1
Authority
CA
Canada
Prior art keywords
user system
originating user
message
return
detection sensor
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Abandoned
Application number
CA002600517A
Other languages
English (en)
French (fr)
Inventor
James F. Riordan
Diego M. Zamboni
Yann Duponchel
Rudiger Rissmann
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
International Business Machines Corp
Original Assignee
Individual
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Individual filed Critical Individual
Publication of CA2600517A1 publication Critical patent/CA2600517A1/en
Abandoned legal-status Critical Current

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/14Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1441Countermeasures against malicious traffic
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L12/00Data switching networks
    • H04L12/02Details
    • H04L12/22Arrangements for preventing the taking of data from a data transmission channel without authorisation
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/14Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1408Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/14Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1441Countermeasures against malicious traffic
    • H04L63/1491Countermeasures against malicious traffic using deception as countermeasure, e.g. honeypots, honeynets, decoys or entrapment

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)
  • Computer And Data Communications (AREA)
  • Information Transfer Between Computers (AREA)
CA002600517A 2005-03-24 2006-02-21 Network attack detection Abandoned CA2600517A1 (en)

Applications Claiming Priority (3)

Application Number Priority Date Filing Date Title
EP05006462 2005-03-24
EP05006462.5 2005-03-24
PCT/IB2006/050554 WO2006100613A1 (en) 2005-03-24 2006-02-21 Network attack detection

Publications (1)

Publication Number Publication Date
CA2600517A1 true CA2600517A1 (en) 2006-09-28

Family

ID=36716621

Family Applications (1)

Application Number Title Priority Date Filing Date
CA002600517A Abandoned CA2600517A1 (en) 2005-03-24 2006-02-21 Network attack detection

Country Status (9)

Country Link
US (1) US20120096548A1 (https=)
EP (1) EP1866725B1 (https=)
JP (1) JP4753264B2 (https=)
KR (1) KR101090815B1 (https=)
CN (1) CN100561492C (https=)
AT (1) ATE485552T1 (https=)
CA (1) CA2600517A1 (https=)
DE (1) DE602006017668D1 (https=)
WO (1) WO2006100613A1 (https=)

Families Citing this family (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP5476578B2 (ja) * 2009-01-06 2014-04-23 独立行政法人情報通信研究機構 ネットワーク監視システム及びその方法
CN101719906B (zh) * 2009-11-10 2012-05-30 电子科技大学 一种基于蠕虫传播行为的蠕虫检测方法
US10432587B2 (en) 2012-02-21 2019-10-01 Aventail Llc VPN deep packet inspection
WO2023233582A1 (ja) * 2022-06-01 2023-12-07 日本電信電話株式会社 攻撃検知装置、攻撃検知システム、攻撃検知方法および攻撃検知プログラム

Family Cites Families (15)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP3618245B2 (ja) * 1999-03-09 2005-02-09 株式会社日立製作所 ネットワーク監視システム
ATE322790T1 (de) 2002-01-18 2006-04-15 Stonesoft Corp Ueberwachung des datenflusses zur verbesserung des netzwerksicherheitsschutzes
WO2004008700A2 (en) * 2002-07-12 2004-01-22 The Penn State Research Foundation Real-time packet traceback and associated packet marking strategies
JP3794491B2 (ja) * 2002-08-20 2006-07-05 日本電気株式会社 攻撃防御システムおよび攻撃防御方法
JP2004241831A (ja) * 2003-02-03 2004-08-26 Rbec Corp ネットワーク管理システム
CN1450758A (zh) * 2003-05-16 2003-10-22 上海金诺网络安全技术发展股份有限公司 高性能网络入侵检测系统和检测方法
AU2003280126A1 (en) 2003-05-30 2005-01-21 International Business Machines Corporation Detecting network attacks
JP3828523B2 (ja) * 2003-07-16 2006-10-04 株式会社東芝 不正アクセス防御装置及びプログラム
JP2005051588A (ja) * 2003-07-30 2005-02-24 Matsushita Electric Ind Co Ltd 自動フィルタリング方法、および機器
AU2003279517A1 (en) 2003-08-11 2005-02-25 Telecom Italia S.P.A. Method and system for detecting unauthorised use of a communication network
US7992204B2 (en) * 2004-05-02 2011-08-02 Markmonitor, Inc. Enhanced responses to online fraud
CN1322712C (zh) * 2004-05-28 2007-06-20 南京邮电学院 一种实现诱骗网络数据流重定向的方法
US7748040B2 (en) * 2004-07-12 2010-06-29 Architecture Technology Corporation Attack correlation using marked information
JP4680931B2 (ja) * 2004-10-19 2011-05-11 富士通株式会社 不正アクセスプログラム監視処理方法、不正アクセスプログラム監視プログラムおよび不正アクセスプログラム監視装置
JP4421462B2 (ja) * 2004-12-06 2010-02-24 三菱電機株式会社 不正侵入検知システムおよび管理装置

Also Published As

Publication number Publication date
EP1866725B1 (en) 2010-10-20
DE602006017668D1 (de) 2010-12-02
KR101090815B1 (ko) 2011-12-08
WO2006100613A1 (en) 2006-09-28
KR20070114155A (ko) 2007-11-29
JP4753264B2 (ja) 2011-08-24
EP1866725A1 (en) 2007-12-19
ATE485552T1 (de) 2010-11-15
US20120096548A1 (en) 2012-04-19
JP2008535304A (ja) 2008-08-28
CN100561492C (zh) 2009-11-18
CN101147153A (zh) 2008-03-19

Similar Documents

Publication Publication Date Title
CN1771709B (zh) 用于产生网络攻击特征标记的方法和装置
Papadopoulos et al. Cossack: Coordinated suppression of simultaneous attacks
Wu et al. An effective architecture and algorithm for detecting worms with various scan techniques
US10129270B2 (en) Apparatus, system and method for identifying and mitigating malicious network threats
Bailey et al. Data reduction for the scalable automated analysis of distributed darknet traffic
US20100262688A1 (en) Systems, methods, and devices for detecting security vulnerabilities in ip networks
EP1648114A1 (en) System and method for monitoring unauthorised network traffic
EP1678615A2 (en) Policy-based network security management
JP2006319982A (ja) 通信ネットワーク内ワーム特定及び不活化方法及び装置
US20040250158A1 (en) System and method for protecting an IP transmission network against the denial of service attacks
Lukaseder et al. An sdn-based approach for defending against reflective ddos attacks
JP4259183B2 (ja) 情報処理システム、情報処理装置、プログラム、及び通信ネットワークにおける通信の異常を検知する方法
JP2002026907A (ja) 通信ネットワークセキュリティ方法および通信ネットワークのネットワークセキュリティを分析するための方法および通信システムおよびセキュリティホストコンピュータおよび機械で読み出し可能な媒体。
US11153350B2 (en) Determining on-net/off-net status of a client device
EP1866725B1 (en) Network attack detection
Wu et al. Virtual inline: a technique of combining IDS and IPS together in response intrusion
Tupakula et al. DoSTRACK: a system for defending against DoS attacks
Selvaraj et al. Enhancing intrusion detection system performance using firecol protection services based honeypot system
Dimiter et al. Botnet Attack Identification Based on SDN
Stamatelatos A measurement study of BGP Blackhole routing performance
CN114338163A (zh) 互联网的安全处理方法及装置
Zhou et al. Locality-based profile analysis for secondary intrusion detection
Deri et al. Ntop: a Lightweight Open-Source Network IDS

Legal Events

Date Code Title Description
EEER Examination request
FZDE Discontinued

Effective date: 20160223