WO2015129934A8 - 명령제어채널 탐지장치 및 방법 - Google Patents

명령제어채널 탐지장치 및 방법 Download PDF

Info

Publication number
WO2015129934A8
WO2015129934A8 PCT/KR2014/001551 KR2014001551W WO2015129934A8 WO 2015129934 A8 WO2015129934 A8 WO 2015129934A8 KR 2014001551 W KR2014001551 W KR 2014001551W WO 2015129934 A8 WO2015129934 A8 WO 2015129934A8
Authority
WO
WIPO (PCT)
Prior art keywords
inspection data
control channels
basis
sessions
distribution
Prior art date
Application number
PCT/KR2014/001551
Other languages
English (en)
French (fr)
Other versions
WO2015129934A1 (ko
Inventor
김혁준
Original Assignee
(주)나루씨큐리티
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by (주)나루씨큐리티 filed Critical (주)나루씨큐리티
Priority to US15/120,526 priority Critical patent/US10218725B2/en
Publication of WO2015129934A1 publication Critical patent/WO2015129934A1/ko
Publication of WO2015129934A8 publication Critical patent/WO2015129934A8/ko

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/14Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1408Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
    • H04L63/1425Traffic logging, e.g. anomaly detection
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/14Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1441Countermeasures against malicious traffic
    • H04L63/1458Denial of Service
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L2463/00Additional details relating to network architectures or network communication protocols for network security covered by H04L63/00
    • H04L2463/142Denial of service attacks against network infrastructure

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)
  • Computer And Data Communications (AREA)
  • Maintenance And Management Of Digital Transmission (AREA)

Abstract

명령제어채널 탐지장치는 제1망의 적어도 하나의 통신장치와 제2망의 적어도 하나의 통신장치 사이에 생성되는 세션들의 로그 정보를 수집하는 세션 로그 수집부, 상기 로그 정보를 기초로 세션별 검사 데이터를 생성하고, 상기 세션들의 검사 데이터를 기초로 검사 데이터 분포를 계산하는 분석부, 그리고 비정상 분포 판단 기준을 기초로 상기 검사 데이터 분포에서 비정상 분포에 해당하는 검사 데이터 값을 추출하고, 추출한 검사 데이터값에 관계된 세션들을 명령제어채널로 추정하는 판단부를 포함한다.
PCT/KR2014/001551 2014-02-25 2014-02-26 명령제어채널 탐지장치 및 방법 WO2015129934A1 (ko)

Priority Applications (1)

Application Number Priority Date Filing Date Title
US15/120,526 US10218725B2 (en) 2014-02-25 2014-02-26 Device and method for detecting command and control channel

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
KR1020140022130A KR102137089B1 (ko) 2014-02-25 2014-02-25 명령제어채널 탐지장치 및 방법
KR10-2014-0022130 2014-02-25

Publications (2)

Publication Number Publication Date
WO2015129934A1 WO2015129934A1 (ko) 2015-09-03
WO2015129934A8 true WO2015129934A8 (ko) 2015-11-05

Family

ID=54009240

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/KR2014/001551 WO2015129934A1 (ko) 2014-02-25 2014-02-26 명령제어채널 탐지장치 및 방법

Country Status (3)

Country Link
US (1) US10218725B2 (ko)
KR (1) KR102137089B1 (ko)
WO (1) WO2015129934A1 (ko)

Families Citing this family (16)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
KR102137089B1 (ko) 2014-02-25 2020-07-23 (주)나루씨큐리티 명령제어채널 탐지장치 및 방법
EP3286888A1 (en) * 2015-04-24 2018-02-28 Nokia Solutions and Networks Oy Mitigation of malicious software in a mobile communications network
US10721212B2 (en) * 2016-12-19 2020-07-21 General Electric Company Network policy update with operational technology
JP6972714B2 (ja) * 2017-07-04 2021-11-24 富士通株式会社 データ取得プログラム、装置、及び方法
US10462187B2 (en) * 2017-08-28 2019-10-29 General Electric Company Network security policy configuration based on predetermined command groups
KR102423126B1 (ko) * 2018-10-26 2022-07-21 삼성전자주식회사 전자 장치 및 그 제어 방법
CN110636075A (zh) * 2019-09-30 2019-12-31 全球能源互联网研究院有限公司 一种运维管控、运维分析方法及装置
US11824881B2 (en) 2020-04-15 2023-11-21 T-Mobile Usa, Inc. On-demand security layer for a 5G wireless network
US11799878B2 (en) 2020-04-15 2023-10-24 T-Mobile Usa, Inc. On-demand software-defined security service orchestration for a 5G wireless network
US11070982B1 (en) 2020-04-15 2021-07-20 T-Mobile Usa, Inc. Self-cleaning function for a network access node of a network
US11444980B2 (en) 2020-04-15 2022-09-13 T-Mobile Usa, Inc. On-demand wireless device centric security for a 5G wireless network
US11115824B1 (en) 2020-05-14 2021-09-07 T-Mobile Usa, Inc. 5G cybersecurity protection system
US11057774B1 (en) 2020-05-14 2021-07-06 T-Mobile Usa, Inc. Intelligent GNODEB cybersecurity protection system
US11206542B2 (en) 2020-05-14 2021-12-21 T-Mobile Usa, Inc. 5G cybersecurity protection system using personalized signatures
US11552989B1 (en) 2021-11-23 2023-01-10 Radware Ltd. Techniques for generating signatures characterizing advanced application layer flood attack tools
US11582259B1 (en) * 2021-11-23 2023-02-14 Radware Ltd. Characterization of HTTP flood DDoS attacks

Family Cites Families (10)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
KR20050090640A (ko) * 2004-03-09 2005-09-14 유넷시스템주식회사 유해 트래픽 분석 시스템 및 방법
US7627893B2 (en) * 2005-10-20 2009-12-01 International Business Machines Corporation Method and system for dynamic adjustment of computer security based on network activity of users
KR101374009B1 (ko) * 2007-07-09 2014-03-13 주식회사 엘지씨엔에스 이상 트래픽 차단 장치 및 방법
JP2010102385A (ja) * 2008-10-21 2010-05-06 Kddi Corp ユーザ分類装置、広告配信装置、ユーザ分類方法、広告配信方法、およびプログラム
KR101060612B1 (ko) * 2009-07-23 2011-08-31 한신대학교 산학협력단 감사자료 기반의 웹공격 이벤트 추출 시스템 및 방법
US8301786B2 (en) * 2010-02-10 2012-10-30 Cisco Technology, Inc. Application session control using packet inspection
US20150205957A1 (en) * 2010-11-29 2015-07-23 Biocatch Ltd. Method, device, and system of differentiating between a legitimate user and a cyber-attacker
US8966059B2 (en) * 2011-04-06 2015-02-24 Microsoft Technology Licensing, Llc Cached data detection
US10061860B2 (en) * 2011-07-29 2018-08-28 Oath Inc. Method and system for personalizing web page layout
KR102137089B1 (ko) 2014-02-25 2020-07-23 (주)나루씨큐리티 명령제어채널 탐지장치 및 방법

Also Published As

Publication number Publication date
KR102137089B1 (ko) 2020-07-23
WO2015129934A1 (ko) 2015-09-03
US10218725B2 (en) 2019-02-26
KR20150100383A (ko) 2015-09-02
US20170013004A1 (en) 2017-01-12

Similar Documents

Publication Publication Date Title
WO2015129934A8 (ko) 명령제어채널 탐지장치 및 방법
MX2014015941A (es) Metodos y aparato para usar los datos de vibracion para determinar una condicion de un dispositivo de control de procesos.
EP3557819A8 (en) Server failure detection method and system
PH12016501476A1 (en) Method and apparatus for social relation analysis and management
WO2015138497A3 (en) Systems and methods for rapid data analysis
WO2016003555A3 (en) Device, method, apparatus, and computer-readable medium for solar site assessment
EP3562956A4 (en) METHODS, APPARATUS AND SYSTEMS FOR ANALYZING STRAINS OF MICRO-ORGANISMS IN COMPLEX HETEROGENEOUS COMMUNITIES, DETERMINING THEIR INTERACTIONS AND FUNCTIONAL RELATIONSHIPS, AND MANAGEMENT OF DIAGNOSTICS AND BIOLOGICAL STATES BASED ON THEM
MX347584B (es) Sistema, método, aparato y producto de programa de computadora para proporcionar servicios de soporte de dispositivo móvil.
MX342662B (es) Sistema, metodo, aparato y producto de programa informatico para proporcionar servicios de asistencia para dispositivos moviles.
WO2018224055A3 (zh) 多维数据异常检测方法及装置
WO2016094182A3 (en) Network device predictive modeling
MX2016013222A (es) Metodo, aparato y sistema de resolucion de problemas basado en virtualizacion de funciones de red.
MY178261A (en) Method, system, and apparatus for exchanging data between client devices
MX349818B (es) Metodos y aparatos para supervisar presentaciones de medios.
MX2015010234A (es) Metodo y dispositivo para adquirir informacion de usuario.
WO2013040025A3 (en) Methods and apparatus to monitor products in stores
SG11201803902VA (en) Data processing method and apparatus
MX361806B (es) Métodos y sistemas para recomendar configuraciones de comunicación.
MX2018002355A (es) Procedimiento autonomo de monitorizacion y diagnostico de una maquina con base en un analisis de firma electrica.
MX358469B (es) Método y dispositivo para realizar una actualización escalonada.
EP2835791A3 (en) Virtualised ATM
EP2779037A3 (en) Information processing system and information processing method for comparing devices
EP2790127A3 (en) Image processing device, image processing method, and recording medium
MY177559A (en) Apparatus and method for improved concealment of the adaptive codebook in acelp-like concealment employing improved pitch lag estimation
TW201612841A (en) Online learning system, skill evaluation method thereof, and storage media storing the method

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 14883708

Country of ref document: EP

Kind code of ref document: A1

WWE Wipo information: entry into national phase

Ref document number: 15120526

Country of ref document: US

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 14883708

Country of ref document: EP

Kind code of ref document: A1