MX2022008154A - Metodo de proteccion de seguridad de red y dispositivo de proteccion. - Google Patents

Metodo de proteccion de seguridad de red y dispositivo de proteccion.

Info

Publication number
MX2022008154A
MX2022008154A MX2022008154A MX2022008154A MX2022008154A MX 2022008154 A MX2022008154 A MX 2022008154A MX 2022008154 A MX2022008154 A MX 2022008154A MX 2022008154 A MX2022008154 A MX 2022008154A MX 2022008154 A MX2022008154 A MX 2022008154A
Authority
MX
Mexico
Prior art keywords
address
attribute information
data stream
device attribute
network security
Prior art date
Application number
MX2022008154A
Other languages
English (en)
Inventor
Qiang Li
Wu Jiang
Jianwei Yu
Yu Huai
Original Assignee
Huawei Tech Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Huawei Tech Co Ltd filed Critical Huawei Tech Co Ltd
Publication of MX2022008154A publication Critical patent/MX2022008154A/es

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/14Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1408Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
    • H04L63/1416Event detection, e.g. attack signature detection
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/02Network architectures or network communication protocols for network security for separating internal from external traffic, e.g. firewalls
    • H04L63/0227Filtering policies
    • H04L63/0236Filtering by address, protocol, port number or service, e.g. IP-address or URL
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/14Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1408Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/02Network architectures or network communication protocols for network security for separating internal from external traffic, e.g. firewalls
    • H04L63/0227Filtering policies
    • H04L63/0263Rule management
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/14Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1408Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
    • H04L63/1425Traffic logging, e.g. anomaly detection
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/14Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1441Countermeasures against malicious traffic
    • H04L63/1466Active attacks involving interception, injection, modification, spoofing of data unit addresses, e.g. hijacking, packet injection or TCP sequence number attacks

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Business, Economics & Management (AREA)
  • General Business, Economics & Management (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)
  • Computer And Data Communications (AREA)

Abstract

Las modalidades de esta aplicación revelan un método de protección de seguridad de red y un dispositivo de protección, para identificar con precisión si un flujo de datos es ofensivo, a fin de mejorar la precisión de la protección. El método de protección de seguridad de red incluye: recibir un primer flujo de datos, donde el primer flujo de datos incluye una dirección de IP de origen y una dirección de IP de destino, la dirección de IP de origen es una dirección de IP de un primer dispositivo electrónico, y la dirección de IP de destino es una dirección de IP de un primer servidor; determinar la primera información de atributos de dispositivo correspondiente a la dirección de IP de origen; determinar la segunda información de atributos de dispositivo correspondiente a la dirección de IP de destino; y reenviar el primer flujo de datos cuando la primera información de atributos de dispositivo coincide con la segunda información de atributos del dispositivo, o bloquear el primer flujo de datos cuando la primera información de atributos de dispositivo no coincide con la segunda información de atributos de dispositivo.
MX2022008154A 2019-12-31 2020-09-11 Metodo de proteccion de seguridad de red y dispositivo de proteccion. MX2022008154A (es)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201911408206.7A CN113132308B (zh) 2019-12-31 2019-12-31 一种网络安全防护方法及防护设备
PCT/CN2020/114685 WO2021135382A1 (zh) 2019-12-31 2020-09-11 一种网络安全防护方法及防护设备

Publications (1)

Publication Number Publication Date
MX2022008154A true MX2022008154A (es) 2022-07-21

Family

ID=76685902

Family Applications (1)

Application Number Title Priority Date Filing Date
MX2022008154A MX2022008154A (es) 2019-12-31 2020-09-11 Metodo de proteccion de seguridad de red y dispositivo de proteccion.

Country Status (7)

Country Link
US (1) US20220329609A1 (es)
EP (1) EP4050859A4 (es)
JP (1) JP7462757B2 (es)
CN (1) CN113132308B (es)
CA (1) CA3158824A1 (es)
MX (1) MX2022008154A (es)
WO (1) WO2021135382A1 (es)

Families Citing this family (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN114826630A (zh) * 2021-01-22 2022-07-29 华为技术有限公司 防护设备中的流量处理方法及防护设备
US11757929B2 (en) 2021-05-27 2023-09-12 Pantheon Systems, Inc. Traffic-shaping HTTP proxy for denial-of-service protection
CN114363386B (zh) * 2021-12-31 2024-04-12 中控创新(北京)能源技术有限公司 工控安全管理装置和油气管道控制系统

Family Cites Families (18)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2001057554A (ja) 1999-08-17 2001-02-27 Yoshimi Baba クラッカー監視システム
US20020032871A1 (en) * 2000-09-08 2002-03-14 The Regents Of The University Of Michigan Method and system for detecting, tracking and blocking denial of service attacks over a computer network
JP2004038557A (ja) 2002-07-03 2004-02-05 Oki Electric Ind Co Ltd 不正アクセス遮断システム
JP2006148778A (ja) 2004-11-24 2006-06-08 Nippon Telegr & Teleph Corp <Ntt> パケット転送制御装置
JP5088830B2 (ja) 2008-10-30 2012-12-05 岩崎通信機株式会社 パケット通過制御方法
JP5110538B2 (ja) 2009-07-16 2012-12-26 Necアクセステクニカ株式会社 ネットワークシステム、ネットワーク装置、ネットワーク方法及びプログラム
JP5300076B2 (ja) 2009-10-07 2013-09-25 日本電気株式会社 コンピュータシステム、及びコンピュータシステムの監視方法
US9596154B2 (en) * 2013-04-11 2017-03-14 Verizon Patent And Licensing Inc. Classifying client devices in a network
CN103581018B (zh) * 2013-07-26 2017-08-11 北京华为数字技术有限公司 报文发送方法、路由器以及业务交换器
CN105991628A (zh) * 2015-03-24 2016-10-05 杭州迪普科技有限公司 网络攻击的识别方法和装置
CN104901960A (zh) * 2015-05-26 2015-09-09 汉柏科技有限公司 一种基于告警策略的网络安全管理设备及方法
CN106714076A (zh) * 2015-11-12 2017-05-24 中兴通讯股份有限公司 一种触发mtc设备的方法和装置
CN107465651B (zh) * 2016-06-06 2020-10-02 腾讯科技(深圳)有限公司 网络攻击检测方法及装置
CN107426168A (zh) * 2017-05-23 2017-12-01 国网山东省电力公司电力科学研究院 一种网络安全访问处理方法及装置
CN107493276B (zh) * 2017-08-08 2020-04-07 北京神州绿盟信息安全科技股份有限公司 一种网络安全防护的方法及装置
CN108521408B (zh) * 2018-03-22 2021-03-12 平安科技(深圳)有限公司 抵抗网络攻击方法、装置、计算机设备及存储介质
US11122411B2 (en) * 2018-09-14 2021-09-14 RaGaPa Inc. Distributed, crowdsourced internet of things (IoT) discovery and identification using block chain
CN109587156B (zh) 2018-12-17 2021-07-09 广州天懋信息系统股份有限公司 异常网络访问连接识别与阻断方法、系统、介质和设备

Also Published As

Publication number Publication date
CA3158824A1 (en) 2021-07-08
EP4050859A4 (en) 2022-12-28
CN113132308B (zh) 2022-05-17
WO2021135382A1 (zh) 2021-07-08
EP4050859A1 (en) 2022-08-31
CN113132308A (zh) 2021-07-16
US20220329609A1 (en) 2022-10-13
JP7462757B2 (ja) 2024-04-05
JP2023508302A (ja) 2023-03-02

Similar Documents

Publication Publication Date Title
MX2022008154A (es) Metodo de proteccion de seguridad de red y dispositivo de proteccion.
EP3813286A3 (en) Collection of error packet information for network policy enforcement
US9736051B2 (en) Smartap arrangement and methods thereof
US20230224232A1 (en) System and method for extracting identifiers from traffic of an unknown protocol
US9154516B1 (en) Detecting risky network communications based on evaluation using normal and abnormal behavior profiles
US9258289B2 (en) Authentication of IP source addresses
US10666672B2 (en) Collecting domain name system traffic
US8856928B1 (en) Protecting electronic assets using false profiles in social networks
US8904524B1 (en) Detection of fast flux networks
US9246930B2 (en) System and method for pattern matching in a network security device
BR112015032505A2 (pt) dispositivo eletrônico, método para autenticar a comunicação de dispositivo eletrônico e meio legível por computador não transitório
CN104137491A (zh) 通过服务网关管理服务的方法
CN109247065B (zh) 启用不同应用的持续流识别器
US20190104144A1 (en) Enhanced flow-based computer network threat detection
CN105338003A (zh) 一种应用于软件定义网络的防火墙实现方法
PH12019000409A1 (en) Security system for controlling internet of things network access
CN103475746A (zh) 一种终端服务方法及装置
Zhang et al. CMD: A convincing mechanism for MITM detection in SDN
CN104184585A (zh) 一种防范dns洪水攻击的装置和方法
US20170034166A1 (en) Network management apparatus, network management method, and recording medium
Spaulding et al. Thriving on chaos: Proactive detection of command and control domains in internet of things‐scale botnets using DRIFT
US10560480B1 (en) Rule enforcement based on network address requests
CN109361618B (zh) 数据流量标记方法、装置、计算机设备及存储介质
CN105282102B (zh) 数据流处理方法和系统以及IPv6数据处理设备
CN108718277B (zh) 基于路由表的报文转发方法与路由表维护方法及相关装置