WO2009044660A1 - 異常トラフィック検知装置、異常トラフィック検知方法および異常トラフィック検知プログラム - Google Patents

異常トラフィック検知装置、異常トラフィック検知方法および異常トラフィック検知プログラム Download PDF

Info

Publication number
WO2009044660A1
WO2009044660A1 PCT/JP2008/067317 JP2008067317W WO2009044660A1 WO 2009044660 A1 WO2009044660 A1 WO 2009044660A1 JP 2008067317 W JP2008067317 W JP 2008067317W WO 2009044660 A1 WO2009044660 A1 WO 2009044660A1
Authority
WO
WIPO (PCT)
Prior art keywords
traffic
abnormal traffic
amount information
traffic detection
abnormal
Prior art date
Application number
PCT/JP2008/067317
Other languages
English (en)
French (fr)
Inventor
Kazuaki Chikira
Hideo Mori
Original Assignee
Nippon Telegraph And Telephone Corporation
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Nippon Telegraph And Telephone Corporation filed Critical Nippon Telegraph And Telephone Corporation
Priority to CN2008801079028A priority Critical patent/CN101803312B/zh
Priority to US12/679,029 priority patent/US8422386B2/en
Priority to EP08834894A priority patent/EP2187577B1/en
Publication of WO2009044660A1 publication Critical patent/WO2009044660A1/ja
Priority to HK10108662.8A priority patent/HK1142200A1/xx

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/14Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1408Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
    • H04L63/1416Event detection, e.g. attack signature detection
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L43/00Arrangements for monitoring or testing data switching networks
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/14Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1441Countermeasures against malicious traffic
    • H04L63/1458Denial of Service

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

 スイッチを通過するトラフィックの情報を用いて通信装置への異常トラフィックを検知する異常トラフィック検知装置において、トラフィックの量情報を、通信装置毎の量情報テーブルとして記憶する宛先IPアドレスカウント部C1~C4と、新たな宛先IPアドレスを有したトラフィックがスイッチを通過する度にこの宛先IPアドレスに対応する量情報テーブルに新たな宛先IPアドレスの量情報を登録しながら、通信装置毎の量情報テーブルに量情報を格納させるトラフィック分離部21と、量情報テーブル内の量情報に基づいて、スイッチ内を流れるトラフィック量の異常を検知する異常トラフィック判定部J1~J4と、を備える。
PCT/JP2008/067317 2007-10-02 2008-09-25 異常トラフィック検知装置、異常トラフィック検知方法および異常トラフィック検知プログラム WO2009044660A1 (ja)

Priority Applications (4)

Application Number Priority Date Filing Date Title
CN2008801079028A CN101803312B (zh) 2007-10-02 2008-09-25 异常业务检测装置、异常业务检测方法及异常业务检测程序
US12/679,029 US8422386B2 (en) 2007-10-02 2008-09-25 Abnormal traffic detection apparatus, abnormal traffic detection method and abnormal traffic detection program
EP08834894A EP2187577B1 (en) 2007-10-02 2008-09-25 Abnormal traffic detection device, abnormal traffic detection method, and abnormal traffic detection program
HK10108662.8A HK1142200A1 (en) 2007-10-02 2010-09-13 Abnormal traffic detection device, abnormal traffic detection method, and abnormal traffic detection program

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
JP2007258798A JP4667437B2 (ja) 2007-10-02 2007-10-02 異常トラフィック検知装置、異常トラフィック検知方法および異常トラフィック検知プログラム
JP2007-258798 2007-10-02

Publications (1)

Publication Number Publication Date
WO2009044660A1 true WO2009044660A1 (ja) 2009-04-09

Family

ID=40526089

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/JP2008/067317 WO2009044660A1 (ja) 2007-10-02 2008-09-25 異常トラフィック検知装置、異常トラフィック検知方法および異常トラフィック検知プログラム

Country Status (6)

Country Link
US (1) US8422386B2 (ja)
EP (1) EP2187577B1 (ja)
JP (1) JP4667437B2 (ja)
CN (1) CN101803312B (ja)
HK (1) HK1142200A1 (ja)
WO (1) WO2009044660A1 (ja)

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102291411A (zh) * 2011-08-18 2011-12-21 网宿科技股份有限公司 针对dns服务的防ddos攻击方法和系统
CN106027559A (zh) * 2016-07-05 2016-10-12 国家计算机网络与信息安全管理中心 基于网络会话统计特征的大规模网络扫描检测方法

Families Citing this family (41)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
AU2003209194A1 (en) 2002-01-08 2003-07-24 Seven Networks, Inc. Secure transport for mobile communication network
US8438633B1 (en) 2005-04-21 2013-05-07 Seven Networks, Inc. Flexible real-time inbox access
WO2006136660A1 (en) 2005-06-21 2006-12-28 Seven Networks International Oy Maintaining an ip connection in a mobile network
US8805425B2 (en) 2007-06-01 2014-08-12 Seven Networks, Inc. Integrated messaging
JP4667437B2 (ja) 2007-10-02 2011-04-13 日本電信電話株式会社 異常トラフィック検知装置、異常トラフィック検知方法および異常トラフィック検知プログラム
US9002828B2 (en) 2007-12-13 2015-04-07 Seven Networks, Inc. Predictive content delivery
US8862657B2 (en) 2008-01-25 2014-10-14 Seven Networks, Inc. Policy based content service
US20090193338A1 (en) 2008-01-28 2009-07-30 Trevor Fiatal Reducing network and battery consumption during content delivery and playback
US8909759B2 (en) 2008-10-10 2014-12-09 Seven Networks, Inc. Bandwidth measurement
US8838783B2 (en) 2010-07-26 2014-09-16 Seven Networks, Inc. Distributed caching for resource and mobile network traffic management
WO2012018430A1 (en) 2010-07-26 2012-02-09 Seven Networks, Inc. Mobile network traffic coordination across multiple applications
US8775613B2 (en) 2010-10-14 2014-07-08 Electronics And Telecommunications Research Institute Method and system for providing network monitoring, security event collection apparatus and service abnormality detection apparatus for network monitoring
WO2012060995A2 (en) 2010-11-01 2012-05-10 Michael Luna Distributed caching in a wireless network of content delivered for a mobile application over a long-held request
US8843153B2 (en) 2010-11-01 2014-09-23 Seven Networks, Inc. Mobile traffic categorization and policy for network use optimization while preserving user experience
KR20120071123A (ko) * 2010-12-22 2012-07-02 한국전자통신연구원 비정상 트래픽 감지 장치 및 방법
EP2700019B1 (en) 2011-04-19 2019-03-27 Seven Networks, LLC Social caching for device resource sharing and management
WO2012149216A2 (en) 2011-04-27 2012-11-01 Seven Networks, Inc. Mobile device which offloads requests made by a mobile application to a remote entity for conservation of mobile device and network resources and methods therefor
US8934414B2 (en) 2011-12-06 2015-01-13 Seven Networks, Inc. Cellular or WiFi mobile traffic optimization based on public or private network destination
WO2013086225A1 (en) 2011-12-06 2013-06-13 Seven Networks, Inc. A mobile device and method to utilize the failover mechanisms for fault tolerance provided for mobile traffic management and network/device resource conservation
WO2013086447A1 (en) 2011-12-07 2013-06-13 Seven Networks, Inc. Radio-awareness of mobile device for sending server-side control signals using a wireless network optimized transport protocol
GB2498064A (en) 2011-12-07 2013-07-03 Seven Networks Inc Distributed content caching mechanism using a network operator proxy
US20130159511A1 (en) 2011-12-14 2013-06-20 Seven Networks, Inc. System and method for generating a report to a network operator by distributing aggregation of data
US8812695B2 (en) 2012-04-09 2014-08-19 Seven Networks, Inc. Method and system for management of a virtual network connection without heartbeat messages
US20130316675A1 (en) * 2012-05-24 2013-11-28 Seven Networks, Inc. Facilitation of mobile operator billing based on wireless network traffic management and tracking of destination address in conjunction with billing policies
WO2014011216A1 (en) 2012-07-13 2014-01-16 Seven Networks, Inc. Dynamic bandwidth adjustment for browsing or streaming activity in a wireless network based on prediction of user behavior when interacting with mobile applications
JP5958354B2 (ja) * 2013-01-16 2016-07-27 富士通株式会社 通信監視装置、発生予測方法及び発生予測プログラム
US8874761B2 (en) 2013-01-25 2014-10-28 Seven Networks, Inc. Signaling optimization in a wireless network for traffic utilizing proprietary and non-proprietary protocols
US8750123B1 (en) 2013-03-11 2014-06-10 Seven Networks, Inc. Mobile device equipped with mobile network congestion recognition to make intelligent decisions regarding connecting to an operator network
US9065765B2 (en) 2013-07-22 2015-06-23 Seven Networks, Inc. Proxy server associated with a mobile carrier for enhancing mobile traffic management in a mobile network
US9774566B2 (en) * 2013-11-29 2017-09-26 Acer Incorporated Communication method and mobile electronic device using the same
KR102045468B1 (ko) * 2015-07-27 2019-11-15 한국전자통신연구원 네트워크 데이터 분석에 기반한 비정상 연결 행위 탐지 장치 및 방법
CN105306436B (zh) * 2015-09-16 2016-08-24 广东睿江云计算股份有限公司 一种异常流量检测方法
US10021130B2 (en) * 2015-09-28 2018-07-10 Verizon Patent And Licensing Inc. Network state information correlation to detect anomalous conditions
JP6612197B2 (ja) * 2016-08-22 2019-11-27 日本電信電話株式会社 DDoS連携対処装置、DDoS連携対処方法及びプログラム
JP6793524B2 (ja) * 2016-11-01 2020-12-02 株式会社日立製作所 ログ解析システムおよびその方法
JP6760185B2 (ja) * 2017-03-31 2020-09-23 住友電気工業株式会社 中継装置、検知方法および検知プログラム
EP3422659A1 (en) * 2017-06-30 2019-01-02 Thomson Licensing Method of blocking distributed denial of service attacks and corresponding apparatus
US11750622B1 (en) 2017-09-05 2023-09-05 Barefoot Networks, Inc. Forwarding element with a data plane DDoS attack detector
US11108812B1 (en) 2018-04-16 2021-08-31 Barefoot Networks, Inc. Data plane with connection validation circuits
JP6927155B2 (ja) * 2018-05-30 2021-08-25 日本電信電話株式会社 異常検出装置、異常検出方法および異常検出プログラム
CN112583850B (zh) * 2020-12-27 2023-02-24 杭州迪普科技股份有限公司 网络攻击防护方法、装置及系统

Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2003283548A (ja) 2002-03-20 2003-10-03 Nippon Telegr & Teleph Corp <Ntt> パケット処理方法および通信装置
JP2004356906A (ja) * 2003-05-28 2004-12-16 Nippon Telegr & Teleph Corp <Ntt> 攻撃パケット対策システム、攻撃パケット対策方法、攻撃パケット対策プログラム、及び記録媒体
JP2005057408A (ja) * 2003-08-01 2005-03-03 Nippon Telegr & Teleph Corp <Ntt> Upc装置
JP2007116405A (ja) * 2005-10-20 2007-05-10 Alaxala Networks Corp 異常トラヒックの検出方法およびパケット中継装置
JP2008035266A (ja) * 2006-07-28 2008-02-14 Ibm Japan Ltd 情報システムの状態を解析する技術
JP2008258996A (ja) * 2007-04-06 2008-10-23 Alaxala Networks Corp 統計情報収集装置

Family Cites Families (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US6298123B1 (en) * 1998-03-26 2001-10-02 Bell Atlantic Network Services, Inc. Interconnect traffic tracking
US6954462B1 (en) * 2000-07-31 2005-10-11 Cisco Technology, Inc. Method and apparatus for determining a multilayer switching path
JP4480422B2 (ja) 2004-03-05 2010-06-16 富士通株式会社 不正アクセス阻止方法、装置及びシステム並びにプログラム
US9794272B2 (en) * 2006-01-03 2017-10-17 Alcatel Lucent Method and apparatus for monitoring malicious traffic in communication networks
JP4667437B2 (ja) 2007-10-02 2011-04-13 日本電信電話株式会社 異常トラフィック検知装置、異常トラフィック検知方法および異常トラフィック検知プログラム

Patent Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2003283548A (ja) 2002-03-20 2003-10-03 Nippon Telegr & Teleph Corp <Ntt> パケット処理方法および通信装置
JP2004356906A (ja) * 2003-05-28 2004-12-16 Nippon Telegr & Teleph Corp <Ntt> 攻撃パケット対策システム、攻撃パケット対策方法、攻撃パケット対策プログラム、及び記録媒体
JP2005057408A (ja) * 2003-08-01 2005-03-03 Nippon Telegr & Teleph Corp <Ntt> Upc装置
JP2007116405A (ja) * 2005-10-20 2007-05-10 Alaxala Networks Corp 異常トラヒックの検出方法およびパケット中継装置
JP2008035266A (ja) * 2006-07-28 2008-02-14 Ibm Japan Ltd 情報システムの状態を解析する技術
JP2008258996A (ja) * 2007-04-06 2008-10-23 Alaxala Networks Corp 統計情報収集装置

Non-Patent Citations (2)

* Cited by examiner, † Cited by third party
Title
"Network Working Group Request for comments: 3954 Category: Informational", October 2004, article "Cisco Systems NetFlow Services Export Version 9"
See also references of EP2187577A4 *

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102291411A (zh) * 2011-08-18 2011-12-21 网宿科技股份有限公司 针对dns服务的防ddos攻击方法和系统
CN106027559A (zh) * 2016-07-05 2016-10-12 国家计算机网络与信息安全管理中心 基于网络会话统计特征的大规模网络扫描检测方法
CN106027559B (zh) * 2016-07-05 2019-07-05 国家计算机网络与信息安全管理中心 基于网络会话统计特征的大规模网络扫描检测方法

Also Published As

Publication number Publication date
HK1142200A1 (en) 2010-11-26
JP2009089241A (ja) 2009-04-23
US20100220619A1 (en) 2010-09-02
JP4667437B2 (ja) 2011-04-13
EP2187577B1 (en) 2013-01-02
EP2187577A1 (en) 2010-05-19
CN101803312A (zh) 2010-08-11
CN101803312B (zh) 2013-08-14
EP2187577A4 (en) 2011-07-20
US8422386B2 (en) 2013-04-16

Similar Documents

Publication Publication Date Title
WO2009044660A1 (ja) 異常トラフィック検知装置、異常トラフィック検知方法および異常トラフィック検知プログラム
WO2009005650A3 (en) Method and system for redirecting of packets to an intrusion prevention service in a network switch
PL2232783T3 (pl) Sposób przełączania zabezpieczenia Ethernet
WO2008118197A3 (en) Disabled state and state signaling for link aggregation
WO2008088271A8 (en) Lightweight mobility architecture
EP1916812A4 (en) METHOD AND DEVICE FOR RAPID CONVERGENCE
WO2006041957A3 (en) METHODS AND SYSTEMS FOR DETECTING IP ROUTE FAILURE AND FOR DYNAMICALLY RE-ROUTING VoIP SESSIONS IN RESPONSE TO FAILURE
GB2426609B (en) Failover and load balancing
WO2008016558A3 (en) Technique for multiple path forwarding of label-switched data traffic
WO2007084755A3 (en) System, method, and computer program product for ip flow routing
WO2010144585A3 (en) Integrated switch tap arrangement with visual display arrangement and methods thereof
TW200715753A (en) Dynamic port failove
WO2006091947A3 (en) Force diversion apparatus and methods and devices including the same
WO2007081362A3 (en) Force diversion apparatus and methods
ATE411679T1 (de) Routenumschaltverfahren und netzwerkknoteneinrichtung
EP1528731A3 (en) Rerouting MPLS traffic in ring networks
FI20065665A0 (fi) Järjestelmät, menetelmät ja laitteet hienotunnistusmoduuleja varten
EP1998526A4 (en) METHOD, SYSTEM AND DEVICE FOR ROUTING NEWS ON THE BASIS OF IP
WO2008132027A3 (en) Monitoring high speed network traffic via sequentially multiplexed data streams
ATE541387T1 (de) Ordnungsgemässes herunterfahren eines ldp auf spezifischen schnittstellen zwischen label- switching-routern
EP2040807A4 (en) METHOD, SYSTEM AND MEASURING DEVICE FOR MEASURING ATHLETIC PERFORMANCE WITH A WEIGHT STACKING UNIT AND WEIGHT STACKING UNIT
WO2008097605A3 (en) Method and apparatus for flexible interface bypass options in switches
WO2011144088A3 (zh) 一种业务保护方法及接入设备
WO2008103602A3 (en) Traffic routing
WO2009073279A3 (en) Techniques for handling service flows in wireless communication systems

Legal Events

Date Code Title Description
WWE Wipo information: entry into national phase

Ref document number: 200880107902.8

Country of ref document: CN

121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 08834894

Country of ref document: EP

Kind code of ref document: A1

WWE Wipo information: entry into national phase

Ref document number: 2008834894

Country of ref document: EP

WWE Wipo information: entry into national phase

Ref document number: 12679029

Country of ref document: US

NENP Non-entry into the national phase

Ref country code: DE