CN102594623A - 防火墙的数据检测方法及装置 - Google Patents
防火墙的数据检测方法及装置 Download PDFInfo
- Publication number
- CN102594623A CN102594623A CN2012100459282A CN201210045928A CN102594623A CN 102594623 A CN102594623 A CN 102594623A CN 2012100459282 A CN2012100459282 A CN 2012100459282A CN 201210045928 A CN201210045928 A CN 201210045928A CN 102594623 A CN102594623 A CN 102594623A
- Authority
- CN
- China
- Prior art keywords
- application
- data
- application data
- protocol type
- detection
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Granted
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/02—Network architectures or network communication protocols for network security for separating internal from external traffic, e.g. firewalls
- H04L63/0227—Filtering policies
- H04L63/0236—Filtering by address, protocol, port number or service, e.g. IP-address or URL
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L43/00—Arrangements for monitoring or testing data switching networks
- H04L43/02—Capturing of monitoring data
- H04L43/028—Capturing of monitoring data by filtering
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1408—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L41/00—Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
- H04L41/08—Configuration management of networks or network elements
- H04L41/0803—Configuration setting
- H04L41/0813—Configuration setting characterised by the conditions triggering a change of settings
- H04L41/082—Configuration setting characterised by the conditions triggering a change of settings the condition being updates or upgrades of network functionality
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/60—Context-dependent security
- H04W12/67—Risk-dependent, e.g. selecting a security level depending on risk profiles
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
- Computer And Data Communications (AREA)
- Alarm Systems (AREA)
Abstract
Description
Claims (10)
Priority Applications (3)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201210045928.2A CN102594623B (zh) | 2011-12-31 | 2012-02-27 | 防火墙的数据检测方法及装置 |
PCT/CN2012/080569 WO2013097475A1 (zh) | 2011-12-31 | 2012-08-24 | 防火墙的数据检测方法及装置 |
US14/305,723 US9398027B2 (en) | 2011-12-31 | 2014-06-16 | Data detecting method and apparatus for firewall |
Applications Claiming Priority (4)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN2011104598720 | 2011-12-31 | ||
CN201110459872.0 | 2011-12-31 | ||
CN201110459872 | 2011-12-31 | ||
CN201210045928.2A CN102594623B (zh) | 2011-12-31 | 2012-02-27 | 防火墙的数据检测方法及装置 |
Publications (2)
Publication Number | Publication Date |
---|---|
CN102594623A true CN102594623A (zh) | 2012-07-18 |
CN102594623B CN102594623B (zh) | 2015-07-29 |
Family
ID=46482843
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN201210045928.2A Active CN102594623B (zh) | 2011-12-31 | 2012-02-27 | 防火墙的数据检测方法及装置 |
Country Status (3)
Country | Link |
---|---|
US (1) | US9398027B2 (zh) |
CN (1) | CN102594623B (zh) |
WO (1) | WO2013097475A1 (zh) |
Cited By (13)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN103051617A (zh) * | 2012-12-18 | 2013-04-17 | 北京奇虎科技有限公司 | 识别程序的网络行为的方法、装置及系统 |
WO2013097475A1 (zh) * | 2011-12-31 | 2013-07-04 | 华为技术有限公司 | 防火墙的数据检测方法及装置 |
CN104506548A (zh) * | 2014-12-31 | 2015-04-08 | 北京天融信科技有限公司 | 一种数据包重定向装置、虚拟机安全保护方法及系统 |
CN105099821A (zh) * | 2015-07-30 | 2015-11-25 | 北京奇虎科技有限公司 | 基于云的虚拟环境下流量监控的方法和装置 |
CN106022150A (zh) * | 2016-05-30 | 2016-10-12 | 宇龙计算机通信科技(深圳)有限公司 | 一种冻结应用方法以及装置 |
CN103067360B (zh) * | 2012-12-18 | 2016-12-28 | 北京奇虎科技有限公司 | 程序网络行为识别方法及系统 |
CN106936805A (zh) * | 2015-12-31 | 2017-07-07 | 亿阳安全技术有限公司 | 一种网络攻击的防御方法和系统 |
CN107204923A (zh) * | 2017-05-24 | 2017-09-26 | 全讯汇聚网络科技(北京)有限公司 | 一种协议分流方法、系统及路由器 |
CN107306255A (zh) * | 2016-04-21 | 2017-10-31 | 阿里巴巴集团控股有限公司 | 防御流量攻击方法、预设列表生成方法、装置及清洗设备 |
CN107360162A (zh) * | 2017-07-12 | 2017-11-17 | 北京奇艺世纪科技有限公司 | 一种网络应用防护方法和装置 |
CN107465567A (zh) * | 2017-06-29 | 2017-12-12 | 西安交大捷普网络科技有限公司 | 一种数据库防火墙的数据转发方法 |
CN108206828A (zh) * | 2017-12-28 | 2018-06-26 | 浙江宇视科技有限公司 | 一种双重监测安全控制方法及系统 |
CN112165460A (zh) * | 2020-09-10 | 2021-01-01 | 杭州安恒信息技术股份有限公司 | 流量检测方法、装置、计算机设备和存储介质 |
Families Citing this family (3)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US11539741B2 (en) | 2019-09-05 | 2022-12-27 | Bank Of America Corporation | Systems and methods for preventing, through machine learning and access filtering, distributed denial of service (“DDoS”) attacks originating from IoT devices |
CN111193747B (zh) * | 2019-12-31 | 2022-06-10 | 奇安信科技集团股份有限公司 | 报文的威胁检测方法、装置、电子设备和存储介质 |
KR20230068741A (ko) * | 2021-11-11 | 2023-05-18 | 한국전자통신연구원 | 디지털 방송 송수신 방법 및 장치 |
Citations (2)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN101052046A (zh) * | 2007-05-22 | 2007-10-10 | 网御神州科技(北京)有限公司 | 一种用于防火墙的防病毒方法及装置 |
CN101599922A (zh) * | 2008-06-02 | 2009-12-09 | 北京华凯兴网络科技有限公司 | 应用层协议病毒防护网关 |
Family Cites Families (9)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US9392002B2 (en) * | 2002-01-31 | 2016-07-12 | Nokia Technologies Oy | System and method of providing virus protection at a gateway |
US8112800B1 (en) * | 2007-11-08 | 2012-02-07 | Juniper Networks, Inc. | Multi-layered application classification and decoding |
CN101459660A (zh) | 2007-12-13 | 2009-06-17 | 国际商业机器公司 | 用于集成多个威胁安全服务的方法及其设备 |
CN101834833B (zh) * | 2009-03-13 | 2014-12-24 | 瞻博网络公司 | 对分布式拒绝服务攻击的服务器防护 |
CN101547207A (zh) | 2009-05-07 | 2009-09-30 | 杭州迪普科技有限公司 | 一种基于应用行为模式的协议识别控制方法和设备 |
CN102075503A (zh) * | 2009-11-24 | 2011-05-25 | 北京网御星云信息技术有限公司 | 一种基于云计算的网络入侵防护系统 |
US8291258B2 (en) | 2010-01-08 | 2012-10-16 | Juniper Networks, Inc. | High availability for network security devices |
CN101789905A (zh) | 2010-02-05 | 2010-07-28 | 杭州华三通信技术有限公司 | 防止未知组播攻击cpu的方法和设备 |
CN102594623B (zh) * | 2011-12-31 | 2015-07-29 | 华为数字技术(成都)有限公司 | 防火墙的数据检测方法及装置 |
-
2012
- 2012-02-27 CN CN201210045928.2A patent/CN102594623B/zh active Active
- 2012-08-24 WO PCT/CN2012/080569 patent/WO2013097475A1/zh active Application Filing
-
2014
- 2014-06-16 US US14/305,723 patent/US9398027B2/en active Active
Patent Citations (2)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN101052046A (zh) * | 2007-05-22 | 2007-10-10 | 网御神州科技(北京)有限公司 | 一种用于防火墙的防病毒方法及装置 |
CN101599922A (zh) * | 2008-06-02 | 2009-12-09 | 北京华凯兴网络科技有限公司 | 应用层协议病毒防护网关 |
Cited By (20)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
WO2013097475A1 (zh) * | 2011-12-31 | 2013-07-04 | 华为技术有限公司 | 防火墙的数据检测方法及装置 |
US9398027B2 (en) | 2011-12-31 | 2016-07-19 | Huawei Technologies Co., Ltd. | Data detecting method and apparatus for firewall |
CN103067360B (zh) * | 2012-12-18 | 2016-12-28 | 北京奇虎科技有限公司 | 程序网络行为识别方法及系统 |
CN103051617B (zh) * | 2012-12-18 | 2015-09-02 | 北京奇虎科技有限公司 | 识别程序的网络行为的方法、装置及系统 |
CN103051617A (zh) * | 2012-12-18 | 2013-04-17 | 北京奇虎科技有限公司 | 识别程序的网络行为的方法、装置及系统 |
CN104506548A (zh) * | 2014-12-31 | 2015-04-08 | 北京天融信科技有限公司 | 一种数据包重定向装置、虚拟机安全保护方法及系统 |
CN105099821B (zh) * | 2015-07-30 | 2020-05-12 | 奇安信科技集团股份有限公司 | 基于云的虚拟环境下流量监控的方法和装置 |
CN105099821A (zh) * | 2015-07-30 | 2015-11-25 | 北京奇虎科技有限公司 | 基于云的虚拟环境下流量监控的方法和装置 |
CN106936805B (zh) * | 2015-12-31 | 2019-06-04 | 亿阳安全技术有限公司 | 一种网络攻击的防御方法和系统 |
CN106936805A (zh) * | 2015-12-31 | 2017-07-07 | 亿阳安全技术有限公司 | 一种网络攻击的防御方法和系统 |
CN107306255A (zh) * | 2016-04-21 | 2017-10-31 | 阿里巴巴集团控股有限公司 | 防御流量攻击方法、预设列表生成方法、装置及清洗设备 |
CN106022150A (zh) * | 2016-05-30 | 2016-10-12 | 宇龙计算机通信科技(深圳)有限公司 | 一种冻结应用方法以及装置 |
CN107204923B (zh) * | 2017-05-24 | 2020-06-02 | 全讯汇聚网络科技(北京)有限公司 | 一种协议分流方法、系统及路由器 |
CN107204923A (zh) * | 2017-05-24 | 2017-09-26 | 全讯汇聚网络科技(北京)有限公司 | 一种协议分流方法、系统及路由器 |
CN107465567A (zh) * | 2017-06-29 | 2017-12-12 | 西安交大捷普网络科技有限公司 | 一种数据库防火墙的数据转发方法 |
CN107465567B (zh) * | 2017-06-29 | 2021-05-07 | 西安交大捷普网络科技有限公司 | 一种数据库防火墙的数据转发方法 |
CN107360162A (zh) * | 2017-07-12 | 2017-11-17 | 北京奇艺世纪科技有限公司 | 一种网络应用防护方法和装置 |
CN108206828A (zh) * | 2017-12-28 | 2018-06-26 | 浙江宇视科技有限公司 | 一种双重监测安全控制方法及系统 |
CN108206828B (zh) * | 2017-12-28 | 2021-03-09 | 浙江宇视科技有限公司 | 一种双重监测安全控制方法及系统 |
CN112165460A (zh) * | 2020-09-10 | 2021-01-01 | 杭州安恒信息技术股份有限公司 | 流量检测方法、装置、计算机设备和存储介质 |
Also Published As
Publication number | Publication date |
---|---|
US9398027B2 (en) | 2016-07-19 |
CN102594623B (zh) | 2015-07-29 |
WO2013097475A1 (zh) | 2013-07-04 |
US20140298466A1 (en) | 2014-10-02 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
CN102594623A (zh) | 防火墙的数据检测方法及装置 | |
US9923909B2 (en) | System and method for providing a self-monitoring, self-reporting, and self-repairing virtual asset configured for extrusion and intrusion detection and threat scoring in a cloud computing environment | |
CN110495138B (zh) | 工业控制系统及其网络安全的监视方法 | |
US10084816B2 (en) | Protocol based detection of suspicious network traffic | |
CN100361452C (zh) | 响应拒绝服务攻击的方法和设备 | |
CN110730175B (zh) | 一种基于威胁情报的僵尸网络检测方法及检测系统 | |
US20160197951A1 (en) | Method and system for virtual asset assisted extrusion and intrusion detection and threat scoring in a cloud computing environment | |
EP2161898B1 (en) | Method and system for defending DDoS attack | |
EP1850236A1 (en) | Communication control apparatus | |
KR101236822B1 (ko) | Arp록킹 기능을 이용한 arp스푸핑 공격 탐지 방법과 그 방법을 실행하기 위한 프로그램이 기록된 기록매체 | |
US20100154032A1 (en) | System and Method for Classification of Unwanted or Malicious Software Through the Identification of Encrypted Data Communication | |
CN103746956A (zh) | 虚拟蜜罐 | |
CN101399835A (zh) | 用于虚拟系统上动态切换和实时安全性控制的方法和设备 | |
KR102464629B1 (ko) | 보안 레벨 기반의 계층적 아키텍처를 이용한 이메일 보안 서비스 제공 장치 및 그 동작 방법 | |
CN110266670A (zh) | 一种终端网络外联行为的处理方法及装置 | |
CN103338211A (zh) | 一种恶意url鉴定方法及装置 | |
JP2009504100A (ja) | IPネットワークにおいて標的被害者自己識別及び制御によってDoS攻撃を防御する方法 | |
JP6904709B2 (ja) | 悪意の電子メッセージを検出するための技術 | |
CN111859374B (zh) | 社会工程学攻击事件的检测方法、装置以及系统 | |
EP3797497B1 (en) | Attack source tracing in sfc overlay network | |
US20200067970A1 (en) | Botnet Mitigation | |
CN1606723A (zh) | 对付通过电子邮件自传播的计算机病毒 | |
EP3349138B1 (en) | Communication destination determination device, communication destination determination method, and recording medium | |
CN106209867B (zh) | 一种高级威胁防御方法及系统 | |
CN112751861A (zh) | 一种基于密网和网络大数据的恶意邮件检测方法及系统 |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
C06 | Publication | ||
PB01 | Publication | ||
C10 | Entry into substantive examination | ||
SE01 | Entry into force of request for substantive examination | ||
C53 | Correction of patent of invention or patent application | ||
CB02 | Change of applicant information |
Address after: 611731 Chengdu high tech Zone, Sichuan, West Park, Qingshui River Applicant after: HUAWEI DIGITAL TECHNOLOGIES (CHENG DU) Co.,Ltd. Address before: 611731 Chengdu high tech Zone, Sichuan, West Park, Qingshui River Applicant before: CHENGDU HUAWEI SYMANTEC TECHNOLOGIES Co.,Ltd. |
|
COR | Change of bibliographic data |
Free format text: CORRECT: APPLICANT; FROM: CHENGDU HUAWEI SYMANTEC TECHNOLOGIES CO., LTD. TO: HUAWEI DIGITAL TECHNOLOGY (CHENGDU) CO., LTD. |
|
C14 | Grant of patent or utility model | ||
GR01 | Patent grant | ||
TR01 | Transfer of patent right | ||
TR01 | Transfer of patent right |
Effective date of registration: 20220901 Address after: No. 1899 Xiyuan Avenue, high tech Zone (West District), Chengdu, Sichuan 610041 Patentee after: Chengdu Huawei Technologies Co.,Ltd. Address before: 611731 Qingshui River District, Chengdu hi tech Zone, Sichuan, China Patentee before: HUAWEI DIGITAL TECHNOLOGIES (CHENG DU) Co.,Ltd. |