首页> 外国专利> METHODS AND DEVICES FOR AUTOMATICALLY DETECTING ATTACK SIGNATURES AND GENERATING ATTACK SIGNATURE IDENTIFICATIONS

METHODS AND DEVICES FOR AUTOMATICALLY DETECTING ATTACK SIGNATURES AND GENERATING ATTACK SIGNATURE IDENTIFICATIONS

机译:自动检测攻击签名并生成攻击签名的方法和设备

摘要

Network traffic management apparatuses, systems, methods, and computer-readable media for automatically detecting attack signatures and generating attack signature identifications, involving: collecting a stable dataset during a stable time; determining whether a cyber-attack is detected; when a cyber-attack is detected, periodically generating attack signatures and updating an enforcer with the attack signatures, the attack signatures representing dynamic rules to be enforced; validating the dynamic rules via a long-time validation mechanism, validating involving considering behavior of each dynamic rule after the cyber-attack and during a new cyber-attack and ranking each dynamic rule using the stable dataset, thereby generating persistent rules having a dynamic rule; exporting the persistent rules to a security enforcer; introducing the persistent rules to a persistent rule revocater; determining whether export of an unrevoked persistent rule is requested; and if requested, exporting the unrevoked persistent rule of the persistent rules through a mitigator and collecting statistics.
机译:用于自动检测攻击特征并生成攻击特征的网络流量管理装置,系统,方法和计算机可读介质,包括:在稳定时间内收集稳定数据集;确定是否检测到网络攻击;当检测到网络攻击时,定期生成攻击签名并用攻击签名更新执行者,这些攻击签名代表要执行的动态规则;通过长期验证机制验证动态规则,进行验证包括考虑在网络攻击之后和新的网络攻击期间每个动态规则的行为,并使用稳定的数据集对每个动态规则进行排名,从而生成具有动态规则的持久性规则;将持久性规则导出到安全实施者;将持久性规则引入持久性规则撤销器;确定是否请求导出未撤销的持久规则;如果需要,则通过缓解器导出持久规则中未被撤销的持久规则并收集统计信息。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号