CN101051966B - 一种网络入侵行为检测系统及检测方法 - Google Patents
一种网络入侵行为检测系统及检测方法 Download PDFInfo
- Publication number
- CN101051966B CN101051966B CN2007101080003A CN200710108000A CN101051966B CN 101051966 B CN101051966 B CN 101051966B CN 2007101080003 A CN2007101080003 A CN 2007101080003A CN 200710108000 A CN200710108000 A CN 200710108000A CN 101051966 B CN101051966 B CN 101051966B
- Authority
- CN
- China
- Prior art keywords
- network
- message
- stream
- reorganization
- speed cache
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Active
Links
- 238000000034 method Methods 0.000 title claims abstract description 9
- 230000009545 invasion Effects 0.000 title claims abstract description 6
- 238000001514 detection method Methods 0.000 claims description 27
- 230000008521 reorganization Effects 0.000 claims description 21
- 230000006399 behavior Effects 0.000 claims description 13
- 241001672694 Citrus reticulata Species 0.000 claims 2
- 238000012217 deletion Methods 0.000 claims 2
- 230000037430 deletion Effects 0.000 claims 2
- 238000005215 recombination Methods 0.000 claims 2
- 230000006798 recombination Effects 0.000 claims 2
- 230000007704 transition Effects 0.000 claims 2
- 239000000284 extract Substances 0.000 abstract description 2
- 230000000694 effects Effects 0.000 description 3
- 238000005516 engineering process Methods 0.000 description 3
- 238000010276 construction Methods 0.000 description 2
- 230000006870 function Effects 0.000 description 2
- 238000007689 inspection Methods 0.000 description 2
- 238000010586 diagram Methods 0.000 description 1
- 230000002349 favourable effect Effects 0.000 description 1
- 238000003672 processing method Methods 0.000 description 1
- 238000010188 recombinant method Methods 0.000 description 1
Images
Landscapes
- Data Exchanges In Wide-Area Networks (AREA)
- Computer And Data Communications (AREA)
Abstract
Description
Claims (2)
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN2007101080003A CN101051966B (zh) | 2007-05-22 | 2007-05-22 | 一种网络入侵行为检测系统及检测方法 |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN2007101080003A CN101051966B (zh) | 2007-05-22 | 2007-05-22 | 一种网络入侵行为检测系统及检测方法 |
Publications (2)
Publication Number | Publication Date |
---|---|
CN101051966A CN101051966A (zh) | 2007-10-10 |
CN101051966B true CN101051966B (zh) | 2010-06-09 |
Family
ID=38783172
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN2007101080003A Active CN101051966B (zh) | 2007-05-22 | 2007-05-22 | 一种网络入侵行为检测系统及检测方法 |
Country Status (1)
Country | Link |
---|---|
CN (1) | CN101051966B (zh) |
Families Citing this family (5)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN101459489B (zh) * | 2007-12-11 | 2011-12-07 | 中兴通讯股份有限公司 | 深度报文检测设备和方法 |
CN101789885B (zh) * | 2009-01-23 | 2012-09-05 | 英业达股份有限公司 | 网络入侵检测系统 |
CN102404213B (zh) * | 2011-11-18 | 2014-09-10 | 盛科网络(苏州)有限公司 | 报文缓存管理方法及系统 |
US10298606B2 (en) * | 2017-01-06 | 2019-05-21 | Juniper Networks, Inc | Apparatus, system, and method for accelerating security inspections using inline pattern matching |
CN110035013A (zh) * | 2019-02-28 | 2019-07-19 | 郑州轨道交通信息技术研究院 | 一种基于工控协议配置文件的流重组实现方法 |
Citations (3)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN1529248A (zh) * | 2003-10-20 | 2004-09-15 | 北京启明星辰信息技术有限公司 | 网络入侵行为关联事件的检测方法及系统 |
CN1738257A (zh) * | 2004-12-31 | 2006-02-22 | 北京大学 | 基于应用协议检测引擎的网络入侵检测系统和方法 |
CN1909488A (zh) * | 2006-08-30 | 2007-02-07 | 北京启明星辰信息技术有限公司 | 一种结合病毒检测与入侵检测的方法及系统 |
-
2007
- 2007-05-22 CN CN2007101080003A patent/CN101051966B/zh active Active
Patent Citations (3)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN1529248A (zh) * | 2003-10-20 | 2004-09-15 | 北京启明星辰信息技术有限公司 | 网络入侵行为关联事件的检测方法及系统 |
CN1738257A (zh) * | 2004-12-31 | 2006-02-22 | 北京大学 | 基于应用协议检测引擎的网络入侵检测系统和方法 |
CN1909488A (zh) * | 2006-08-30 | 2007-02-07 | 北京启明星辰信息技术有限公司 | 一种结合病毒检测与入侵检测的方法及系统 |
Non-Patent Citations (2)
Title |
---|
应用级防火墙 走出概念泡沫.计算机安全 4.2004,(4),第26页. |
应用级防火墙 走出概念泡沫.计算机安全 4.2004,(4),第26页. * |
Also Published As
Publication number | Publication date |
---|---|
CN101051966A (zh) | 2007-10-10 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
CN101051966B (zh) | 一种网络入侵行为检测系统及检测方法 | |
CN100556031C (zh) | 智能集成网络安全设备 | |
CN107959690B (zh) | 基于软件定义网络的DDoS攻击跨层协同防御方法 | |
EP1774716B1 (en) | Inline intrusion detection using a single physical port | |
CN100558089C (zh) | 一种基于网络过滤器的内容过滤网关实现方法 | |
US8751787B2 (en) | Method and device for integrating multiple threat security services | |
EP2226976B1 (en) | Monitoring fragmented data flows | |
US20140298399A1 (en) | Apparatus and method for detecting anomality sign in controll system | |
US20040255162A1 (en) | Security gateway system and method for intrusion detection | |
CN110401642A (zh) | 一种工控流量的采集与协议解析方法 | |
CN102067532A (zh) | 分组片段的处理 | |
CN108701187A (zh) | 混合硬件软件分布式威胁分析 | |
CN104022999A (zh) | 基于协议分析的网络数据处理方法及系统 | |
KR20090006838A (ko) | 악의적 공격 검출 시스템 및 이에 연계된 유용한 방법 | |
CN112995238B (zh) | 一种减轻DDoS攻击的方法、可编程交换机及SDN控制器 | |
JP2007184799A (ja) | パケット通信装置 | |
EP3270572A1 (en) | A system for secure communication | |
CN104618377A (zh) | 基于NetFlow的僵尸网络检测系统与检测方法 | |
EP3720075B1 (en) | Data transmission method and virtual switch | |
CN104796405B (zh) | 反弹连接检测方法和装置 | |
CN104796354A (zh) | 一种乱序数据包字符串匹配方法及系统 | |
CN101213813A (zh) | 借助目标受害者的自识别和控制,防御ip网络中服务拒绝攻击的方法 | |
CN101902461B (zh) | 一种数据流内容过滤的方法及装置 | |
CN110138759A (zh) | SDN环境下针对Packet-In注入攻击的轻量级自适应检测方法及系统 | |
US20120177046A1 (en) | Network node |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
C06 | Publication | ||
PB01 | Publication | ||
C10 | Entry into substantive examination | ||
SE01 | Entry into force of request for substantive examination | ||
C14 | Grant of patent or utility model | ||
GR01 | Patent grant | ||
C56 | Change in the name or address of the patentee |
Owner name: WANGSHEN INFORMATION TECHNOLOGY (BEIJING) CO., LTD Free format text: FORMER NAME: WANGYUSHENZHOU TECH (BEIJING) CO., LTD. |
|
CP01 | Change in the name or title of a patent holder |
Address after: 100085 Beijing city Haidian District Zone Development Road No. 7 Pioneer Building Patentee after: LEGENDSEC INFORMATION TECHNOLOGY (BEIJING) Inc. Address before: 100085 Beijing city Haidian District Zone Development Road No. 7 Pioneer Building Patentee before: LEGENDSEC TECHNOLOGY Co.,Ltd. |
|
ASS | Succession or assignment of patent right |
Owner name: LEGENDSEC TECHNOLOGY (BEIJING) CO., LTD. Effective date: 20121224 |
|
C41 | Transfer of patent application or patent right or utility model | ||
TR01 | Transfer of patent right |
Effective date of registration: 20121224 Address after: 100085 Beijing city Haidian District on the pioneering Road No. 7 building two layer 1 pioneer Patentee after: LEGENDSEC INFORMATION TECHNOLOGY (BEIJING) Inc. Patentee after: Legendsec Technology (Beijing) Co.,Ltd. Address before: 100085 Beijing city Haidian District Zone Development Road No. 7 Pioneer Building Patentee before: LEGENDSEC INFORMATION TECHNOLOGY (BEIJING) INC. |
|
DD01 | Delivery of document by public notice |
Addressee: LEGENDSEC INFORMATION TECHNOLOGY (BEIJING) INC. Document name: Notification of Passing Examination on Formalities |
|
CP03 | Change of name, title or address |
Address after: 2nd Floor, Building 1, Yard 26, Xizhimenwai South Road, Xicheng District, Beijing Patentee after: Qianxin Wangshen information technology (Beijing) Co.,Ltd. Patentee after: Legendsec Technology (Beijing) Co.,Ltd. Address before: 100085, 7, Pioneer Road, Haidian District, Beijing, building two, 1 Patentee before: LEGENDSEC INFORMATION TECHNOLOGY (BEIJING) Inc. Patentee before: Legendsec Technology (Beijing) Co.,Ltd. |
|
CP03 | Change of name, title or address |