首页> 外国专利> Method of analysis of information flows and determine the status of a secure network based on adaptive FORECASTING AND DEVICE FOR ITS IMPLEMENTATION

Method of analysis of information flows and determine the status of a secure network based on adaptive FORECASTING AND DEVICE FOR ITS IMPLEMENTATION

机译:基于自适应预测及其实现的信息流分析和确定安全网络状态的方法

摘要

1. A method of analyzing an information stream and determining the state of the network security based adaptive prediction, comprising the steps of network traffic that is isolated from the flow of information packets transmitted on the TCP / IP protocols, the selected packets extracted from the characteristic parameters for matching IP-address recipient and send a signal recorded on abnormal values ​​in IP-addresses, TCP packet count ratio defined flags SYN and FIN in unit time and record the obtained value as the first with The sign of the abnormal traffic, is calculated intensity information exchange TCP packets per unit time and record the obtained value as a second indication of an anomalous traffic calculated amount of TCP-packet arriving in a unit time and record the obtained value as the third sign of the abnormal traffic, is calculated ratio of the number of packets rejected came to the total number of packets and record the obtained value as the fourth sign of the abnormal traffic detection incorrect IP-addresses recorded signa Previous IP-address of the received characteristic values ​​anomalous traffic normalized and record obtained after the normalization value on the basis of the obtained values ​​is calculated numerical value of the level of traffic abnormality and displays this value on the device output information, characterized in that before allocation of packets of information stream recorded medium weighting values ​​features abnormal traffic prediction unit normalization after the abnormal traffic signs according to the current received
机译:1.一种分析信息流并确定基于网络安全性的自适应预测的状态的方法,该方法包括以下步骤:将网络流量与在TCP / IP协议上传输的信息包的流隔离开来,从中提取选定的包。匹配IP地址接收者并发送记录在IP地址中异常值上的信号的特征参数,TCP数据包计数比率定义单位时间内的标志SYN和FIN,并将获得的值记录为第一个带有异常流量的符号计算每单位时间的强度信息交换TCP数据包,并将获得的值记录为单位时间内到达的TCP数据包的异常流量计算量的第二个指示,并将获取的值记录为异常流量的第三个符号,计算出的拒绝包数与总包数之比,并将获得的值记录为异常tr的第四个符号流量检测不正确的IP地址记录符号a接收到的特征值的异常IP的归一化IP地址归一化,并在归一化值的基础上获得归一化后的记录,计算出交通异常水平的数值并显示该值在设备上输出信息,其特征在于,在分配信息流的数据包之前记录的媒体加权值具有特征,即异常流量预测单元归一化之后,根据当前接收到的异常流量标志

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号