WO2009044660A1 - 異常トラフィック検知装置、異常トラフィック検知方法および異常トラフィック検知プログラム - Google Patents
異常トラフィック検知装置、異常トラフィック検知方法および異常トラフィック検知プログラム Download PDFInfo
- Publication number
- WO2009044660A1 WO2009044660A1 PCT/JP2008/067317 JP2008067317W WO2009044660A1 WO 2009044660 A1 WO2009044660 A1 WO 2009044660A1 JP 2008067317 W JP2008067317 W JP 2008067317W WO 2009044660 A1 WO2009044660 A1 WO 2009044660A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- traffic
- abnormal traffic
- amount information
- traffic detection
- abnormal
- Prior art date
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1408—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
- H04L63/1416—Event detection, e.g. attack signature detection
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L43/00—Arrangements for monitoring or testing data switching networks
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1441—Countermeasures against malicious traffic
- H04L63/1458—Denial of Service
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
スイッチを通過するトラフィックの情報を用いて通信装置への異常トラフィックを検知する異常トラフィック検知装置において、トラフィックの量情報を、通信装置毎の量情報テーブルとして記憶する宛先IPアドレスカウント部C1~C4と、新たな宛先IPアドレスを有したトラフィックがスイッチを通過する度にこの宛先IPアドレスに対応する量情報テーブルに新たな宛先IPアドレスの量情報を登録しながら、通信装置毎の量情報テーブルに量情報を格納させるトラフィック分離部21と、量情報テーブル内の量情報に基づいて、スイッチ内を流れるトラフィック量の異常を検知する異常トラフィック判定部J1~J4と、を備える。
Priority Applications (4)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN2008801079028A CN101803312B (zh) | 2007-10-02 | 2008-09-25 | 异常业务检测装置、异常业务检测方法及异常业务检测程序 |
US12/679,029 US8422386B2 (en) | 2007-10-02 | 2008-09-25 | Abnormal traffic detection apparatus, abnormal traffic detection method and abnormal traffic detection program |
EP08834894A EP2187577B1 (en) | 2007-10-02 | 2008-09-25 | Abnormal traffic detection device, abnormal traffic detection method, and abnormal traffic detection program |
HK10108662.8A HK1142200A1 (en) | 2007-10-02 | 2010-09-13 | Abnormal traffic detection device, abnormal traffic detection method, and abnormal traffic detection program |
Applications Claiming Priority (2)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
JP2007258798A JP4667437B2 (ja) | 2007-10-02 | 2007-10-02 | 異常トラフィック検知装置、異常トラフィック検知方法および異常トラフィック検知プログラム |
JP2007-258798 | 2007-10-02 |
Publications (1)
Publication Number | Publication Date |
---|---|
WO2009044660A1 true WO2009044660A1 (ja) | 2009-04-09 |
Family
ID=40526089
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
PCT/JP2008/067317 WO2009044660A1 (ja) | 2007-10-02 | 2008-09-25 | 異常トラフィック検知装置、異常トラフィック検知方法および異常トラフィック検知プログラム |
Country Status (6)
Country | Link |
---|---|
US (1) | US8422386B2 (ja) |
EP (1) | EP2187577B1 (ja) |
JP (1) | JP4667437B2 (ja) |
CN (1) | CN101803312B (ja) |
HK (1) | HK1142200A1 (ja) |
WO (1) | WO2009044660A1 (ja) |
Cited By (2)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN102291411A (zh) * | 2011-08-18 | 2011-12-21 | 网宿科技股份有限公司 | 针对dns服务的防ddos攻击方法和系统 |
CN106027559A (zh) * | 2016-07-05 | 2016-10-12 | 国家计算机网络与信息安全管理中心 | 基于网络会话统计特征的大规模网络扫描检测方法 |
Families Citing this family (41)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
AU2003209194A1 (en) | 2002-01-08 | 2003-07-24 | Seven Networks, Inc. | Secure transport for mobile communication network |
US8438633B1 (en) | 2005-04-21 | 2013-05-07 | Seven Networks, Inc. | Flexible real-time inbox access |
WO2006136660A1 (en) | 2005-06-21 | 2006-12-28 | Seven Networks International Oy | Maintaining an ip connection in a mobile network |
US8805425B2 (en) | 2007-06-01 | 2014-08-12 | Seven Networks, Inc. | Integrated messaging |
JP4667437B2 (ja) | 2007-10-02 | 2011-04-13 | 日本電信電話株式会社 | 異常トラフィック検知装置、異常トラフィック検知方法および異常トラフィック検知プログラム |
US9002828B2 (en) | 2007-12-13 | 2015-04-07 | Seven Networks, Inc. | Predictive content delivery |
US8862657B2 (en) | 2008-01-25 | 2014-10-14 | Seven Networks, Inc. | Policy based content service |
US20090193338A1 (en) | 2008-01-28 | 2009-07-30 | Trevor Fiatal | Reducing network and battery consumption during content delivery and playback |
US8909759B2 (en) | 2008-10-10 | 2014-12-09 | Seven Networks, Inc. | Bandwidth measurement |
US8838783B2 (en) | 2010-07-26 | 2014-09-16 | Seven Networks, Inc. | Distributed caching for resource and mobile network traffic management |
WO2012018430A1 (en) | 2010-07-26 | 2012-02-09 | Seven Networks, Inc. | Mobile network traffic coordination across multiple applications |
US8775613B2 (en) | 2010-10-14 | 2014-07-08 | Electronics And Telecommunications Research Institute | Method and system for providing network monitoring, security event collection apparatus and service abnormality detection apparatus for network monitoring |
WO2012060995A2 (en) | 2010-11-01 | 2012-05-10 | Michael Luna | Distributed caching in a wireless network of content delivered for a mobile application over a long-held request |
US8843153B2 (en) | 2010-11-01 | 2014-09-23 | Seven Networks, Inc. | Mobile traffic categorization and policy for network use optimization while preserving user experience |
KR20120071123A (ko) * | 2010-12-22 | 2012-07-02 | 한국전자통신연구원 | 비정상 트래픽 감지 장치 및 방법 |
EP2700019B1 (en) | 2011-04-19 | 2019-03-27 | Seven Networks, LLC | Social caching for device resource sharing and management |
WO2012149216A2 (en) | 2011-04-27 | 2012-11-01 | Seven Networks, Inc. | Mobile device which offloads requests made by a mobile application to a remote entity for conservation of mobile device and network resources and methods therefor |
US8934414B2 (en) | 2011-12-06 | 2015-01-13 | Seven Networks, Inc. | Cellular or WiFi mobile traffic optimization based on public or private network destination |
WO2013086225A1 (en) | 2011-12-06 | 2013-06-13 | Seven Networks, Inc. | A mobile device and method to utilize the failover mechanisms for fault tolerance provided for mobile traffic management and network/device resource conservation |
WO2013086447A1 (en) | 2011-12-07 | 2013-06-13 | Seven Networks, Inc. | Radio-awareness of mobile device for sending server-side control signals using a wireless network optimized transport protocol |
GB2498064A (en) | 2011-12-07 | 2013-07-03 | Seven Networks Inc | Distributed content caching mechanism using a network operator proxy |
US20130159511A1 (en) | 2011-12-14 | 2013-06-20 | Seven Networks, Inc. | System and method for generating a report to a network operator by distributing aggregation of data |
US8812695B2 (en) | 2012-04-09 | 2014-08-19 | Seven Networks, Inc. | Method and system for management of a virtual network connection without heartbeat messages |
US20130316675A1 (en) * | 2012-05-24 | 2013-11-28 | Seven Networks, Inc. | Facilitation of mobile operator billing based on wireless network traffic management and tracking of destination address in conjunction with billing policies |
WO2014011216A1 (en) | 2012-07-13 | 2014-01-16 | Seven Networks, Inc. | Dynamic bandwidth adjustment for browsing or streaming activity in a wireless network based on prediction of user behavior when interacting with mobile applications |
JP5958354B2 (ja) * | 2013-01-16 | 2016-07-27 | 富士通株式会社 | 通信監視装置、発生予測方法及び発生予測プログラム |
US8874761B2 (en) | 2013-01-25 | 2014-10-28 | Seven Networks, Inc. | Signaling optimization in a wireless network for traffic utilizing proprietary and non-proprietary protocols |
US8750123B1 (en) | 2013-03-11 | 2014-06-10 | Seven Networks, Inc. | Mobile device equipped with mobile network congestion recognition to make intelligent decisions regarding connecting to an operator network |
US9065765B2 (en) | 2013-07-22 | 2015-06-23 | Seven Networks, Inc. | Proxy server associated with a mobile carrier for enhancing mobile traffic management in a mobile network |
US9774566B2 (en) * | 2013-11-29 | 2017-09-26 | Acer Incorporated | Communication method and mobile electronic device using the same |
KR102045468B1 (ko) * | 2015-07-27 | 2019-11-15 | 한국전자통신연구원 | 네트워크 데이터 분석에 기반한 비정상 연결 행위 탐지 장치 및 방법 |
CN105306436B (zh) * | 2015-09-16 | 2016-08-24 | 广东睿江云计算股份有限公司 | 一种异常流量检测方法 |
US10021130B2 (en) * | 2015-09-28 | 2018-07-10 | Verizon Patent And Licensing Inc. | Network state information correlation to detect anomalous conditions |
JP6612197B2 (ja) * | 2016-08-22 | 2019-11-27 | 日本電信電話株式会社 | DDoS連携対処装置、DDoS連携対処方法及びプログラム |
JP6793524B2 (ja) * | 2016-11-01 | 2020-12-02 | 株式会社日立製作所 | ログ解析システムおよびその方法 |
JP6760185B2 (ja) * | 2017-03-31 | 2020-09-23 | 住友電気工業株式会社 | 中継装置、検知方法および検知プログラム |
EP3422659A1 (en) * | 2017-06-30 | 2019-01-02 | Thomson Licensing | Method of blocking distributed denial of service attacks and corresponding apparatus |
US11750622B1 (en) | 2017-09-05 | 2023-09-05 | Barefoot Networks, Inc. | Forwarding element with a data plane DDoS attack detector |
US11108812B1 (en) | 2018-04-16 | 2021-08-31 | Barefoot Networks, Inc. | Data plane with connection validation circuits |
JP6927155B2 (ja) * | 2018-05-30 | 2021-08-25 | 日本電信電話株式会社 | 異常検出装置、異常検出方法および異常検出プログラム |
CN112583850B (zh) * | 2020-12-27 | 2023-02-24 | 杭州迪普科技股份有限公司 | 网络攻击防护方法、装置及系统 |
Citations (6)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
JP2003283548A (ja) | 2002-03-20 | 2003-10-03 | Nippon Telegr & Teleph Corp <Ntt> | パケット処理方法および通信装置 |
JP2004356906A (ja) * | 2003-05-28 | 2004-12-16 | Nippon Telegr & Teleph Corp <Ntt> | 攻撃パケット対策システム、攻撃パケット対策方法、攻撃パケット対策プログラム、及び記録媒体 |
JP2005057408A (ja) * | 2003-08-01 | 2005-03-03 | Nippon Telegr & Teleph Corp <Ntt> | Upc装置 |
JP2007116405A (ja) * | 2005-10-20 | 2007-05-10 | Alaxala Networks Corp | 異常トラヒックの検出方法およびパケット中継装置 |
JP2008035266A (ja) * | 2006-07-28 | 2008-02-14 | Ibm Japan Ltd | 情報システムの状態を解析する技術 |
JP2008258996A (ja) * | 2007-04-06 | 2008-10-23 | Alaxala Networks Corp | 統計情報収集装置 |
Family Cites Families (5)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US6298123B1 (en) * | 1998-03-26 | 2001-10-02 | Bell Atlantic Network Services, Inc. | Interconnect traffic tracking |
US6954462B1 (en) * | 2000-07-31 | 2005-10-11 | Cisco Technology, Inc. | Method and apparatus for determining a multilayer switching path |
JP4480422B2 (ja) | 2004-03-05 | 2010-06-16 | 富士通株式会社 | 不正アクセス阻止方法、装置及びシステム並びにプログラム |
US9794272B2 (en) * | 2006-01-03 | 2017-10-17 | Alcatel Lucent | Method and apparatus for monitoring malicious traffic in communication networks |
JP4667437B2 (ja) | 2007-10-02 | 2011-04-13 | 日本電信電話株式会社 | 異常トラフィック検知装置、異常トラフィック検知方法および異常トラフィック検知プログラム |
-
2007
- 2007-10-02 JP JP2007258798A patent/JP4667437B2/ja active Active
-
2008
- 2008-09-25 EP EP08834894A patent/EP2187577B1/en not_active Not-in-force
- 2008-09-25 WO PCT/JP2008/067317 patent/WO2009044660A1/ja active Application Filing
- 2008-09-25 US US12/679,029 patent/US8422386B2/en active Active
- 2008-09-25 CN CN2008801079028A patent/CN101803312B/zh not_active Expired - Fee Related
-
2010
- 2010-09-13 HK HK10108662.8A patent/HK1142200A1/xx not_active IP Right Cessation
Patent Citations (6)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
JP2003283548A (ja) | 2002-03-20 | 2003-10-03 | Nippon Telegr & Teleph Corp <Ntt> | パケット処理方法および通信装置 |
JP2004356906A (ja) * | 2003-05-28 | 2004-12-16 | Nippon Telegr & Teleph Corp <Ntt> | 攻撃パケット対策システム、攻撃パケット対策方法、攻撃パケット対策プログラム、及び記録媒体 |
JP2005057408A (ja) * | 2003-08-01 | 2005-03-03 | Nippon Telegr & Teleph Corp <Ntt> | Upc装置 |
JP2007116405A (ja) * | 2005-10-20 | 2007-05-10 | Alaxala Networks Corp | 異常トラヒックの検出方法およびパケット中継装置 |
JP2008035266A (ja) * | 2006-07-28 | 2008-02-14 | Ibm Japan Ltd | 情報システムの状態を解析する技術 |
JP2008258996A (ja) * | 2007-04-06 | 2008-10-23 | Alaxala Networks Corp | 統計情報収集装置 |
Non-Patent Citations (2)
Title |
---|
"Network Working Group Request for comments: 3954 Category: Informational", October 2004, article "Cisco Systems NetFlow Services Export Version 9" |
See also references of EP2187577A4 * |
Cited By (3)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN102291411A (zh) * | 2011-08-18 | 2011-12-21 | 网宿科技股份有限公司 | 针对dns服务的防ddos攻击方法和系统 |
CN106027559A (zh) * | 2016-07-05 | 2016-10-12 | 国家计算机网络与信息安全管理中心 | 基于网络会话统计特征的大规模网络扫描检测方法 |
CN106027559B (zh) * | 2016-07-05 | 2019-07-05 | 国家计算机网络与信息安全管理中心 | 基于网络会话统计特征的大规模网络扫描检测方法 |
Also Published As
Publication number | Publication date |
---|---|
HK1142200A1 (en) | 2010-11-26 |
JP2009089241A (ja) | 2009-04-23 |
US20100220619A1 (en) | 2010-09-02 |
JP4667437B2 (ja) | 2011-04-13 |
EP2187577B1 (en) | 2013-01-02 |
EP2187577A1 (en) | 2010-05-19 |
CN101803312A (zh) | 2010-08-11 |
CN101803312B (zh) | 2013-08-14 |
EP2187577A4 (en) | 2011-07-20 |
US8422386B2 (en) | 2013-04-16 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
WO2009044660A1 (ja) | 異常トラフィック検知装置、異常トラフィック検知方法および異常トラフィック検知プログラム | |
WO2009005650A3 (en) | Method and system for redirecting of packets to an intrusion prevention service in a network switch | |
PL2232783T3 (pl) | Sposób przełączania zabezpieczenia Ethernet | |
WO2008118197A3 (en) | Disabled state and state signaling for link aggregation | |
WO2008088271A8 (en) | Lightweight mobility architecture | |
EP1916812A4 (en) | METHOD AND DEVICE FOR RAPID CONVERGENCE | |
WO2006041957A3 (en) | METHODS AND SYSTEMS FOR DETECTING IP ROUTE FAILURE AND FOR DYNAMICALLY RE-ROUTING VoIP SESSIONS IN RESPONSE TO FAILURE | |
GB2426609B (en) | Failover and load balancing | |
WO2008016558A3 (en) | Technique for multiple path forwarding of label-switched data traffic | |
WO2007084755A3 (en) | System, method, and computer program product for ip flow routing | |
WO2010144585A3 (en) | Integrated switch tap arrangement with visual display arrangement and methods thereof | |
TW200715753A (en) | Dynamic port failove | |
WO2006091947A3 (en) | Force diversion apparatus and methods and devices including the same | |
WO2007081362A3 (en) | Force diversion apparatus and methods | |
ATE411679T1 (de) | Routenumschaltverfahren und netzwerkknoteneinrichtung | |
EP1528731A3 (en) | Rerouting MPLS traffic in ring networks | |
FI20065665A0 (fi) | Järjestelmät, menetelmät ja laitteet hienotunnistusmoduuleja varten | |
EP1998526A4 (en) | METHOD, SYSTEM AND DEVICE FOR ROUTING NEWS ON THE BASIS OF IP | |
WO2008132027A3 (en) | Monitoring high speed network traffic via sequentially multiplexed data streams | |
ATE541387T1 (de) | Ordnungsgemässes herunterfahren eines ldp auf spezifischen schnittstellen zwischen label- switching-routern | |
EP2040807A4 (en) | METHOD, SYSTEM AND MEASURING DEVICE FOR MEASURING ATHLETIC PERFORMANCE WITH A WEIGHT STACKING UNIT AND WEIGHT STACKING UNIT | |
WO2008097605A3 (en) | Method and apparatus for flexible interface bypass options in switches | |
WO2011144088A3 (zh) | 一种业务保护方法及接入设备 | |
WO2008103602A3 (en) | Traffic routing | |
WO2009073279A3 (en) | Techniques for handling service flows in wireless communication systems |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
WWE | Wipo information: entry into national phase |
Ref document number: 200880107902.8 Country of ref document: CN |
|
121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 08834894 Country of ref document: EP Kind code of ref document: A1 |
|
WWE | Wipo information: entry into national phase |
Ref document number: 2008834894 Country of ref document: EP |
|
WWE | Wipo information: entry into national phase |
Ref document number: 12679029 Country of ref document: US |
|
NENP | Non-entry into the national phase |
Ref country code: DE |