Detecting network attacks
This disclosure generally relates to the generation of a packet signature for packets determined to correspond to a network attack, such as a denial of service ("DoS") attack. Specifically, a set of data packets captured during normal system operations can be analyzed to determine a set of...
Gespeichert in:
Hauptverfasser: | , , |
---|---|
Format: | Patent |
Sprache: | eng |
Schlagworte: | |
Online-Zugang: | Volltext bestellen |
Tags: |
Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
|
Zusammenfassung: | This disclosure generally relates to the generation of a packet signature for packets determined to correspond to a network attack, such as a denial of service ("DoS") attack. Specifically, a set of data packets captured during normal system operations can be analyzed to determine a set of baseline attributes. Additional packets captured during an attack can be compared to the baseline attributes, to determine, for individual packets, a probability that the packet forms a part of the attack. A packet signature can then be generated to identify attributes that are characteristic of the attack. That signature can then be used to filter out packets and mitigate the attack. |
---|