首页> 外国专利> Inter-arrival time intrusion-detection technique to provide enhanced cybersecurity

Inter-arrival time intrusion-detection technique to provide enhanced cybersecurity

机译:到达间隔时间入侵检测技术可提供增强的网络安全性

摘要

The disclosed embodiments relate to a system that performs an intrusion-detection technique to differentiate between packets received from malicious remote users and legitimate local users in a networked computer system. During operation, the system determines arrival times for incoming packets at a node in the networked computer system. Next, the system determines inter-arrival times between the incoming packets from the arrival times. The system then determines a mean cumulative function (MCF) for the inter-arrival times by computing a cumulative sum of the inter-arrival times. Finally, upon detecting a change in a slope of the MCF, the system generates an alarm to indicate that a malicious remote user may be generating some of the incoming packets.
机译:公开的实施例涉及一种执行入侵检测技术以在从联网计算机系统中的恶意远程用户和合法本地用户接收的分组之间进行区分的系统。在操作期间,系统确定传入数据包到达联网计算机系统中某个节点的到达时间。接下来,系统根据到达时间确定传入数据包之间的到达间隔时间。然后,系统通过计算到达间隔时间的累积总和来确定到达间隔时间的平均累积函数(MCF)。最后,在检测到MCF斜率的变化时,系统会生成警报,以指示恶意远程用户可能正在生成某些传入数据包。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号