Invention Grant
- Patent Title: Network traffic analysis to enhance rule-based network security
-
Application No.: US15599211Application Date: 2017-05-18
-
Publication No.: US10091167B2Publication Date: 2018-10-02
- Inventor: Sheng-Tung Hsu , Chien Pang Lee , Pei-Chun Yao
- Applicant: International Business Machines Corporation
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agency: Yee & Associates, P.C.
- Agent Robert Shatto
- Priority: TW102127546A 20130731
- Main IPC: H04L29/06
- IPC: H04L29/06

Abstract:
A method of interpreting a rule and a rule-interpreting apparatus for rule-based security apparatus, and an apparatus implementing the method. The method comprises the following steps: designating a suspicious timeslot; if any packet does not present in the designated timeslot, capturing current incoming packets or capturing other incoming packets in the designated timeslot next time; automatically associating the packets in the designated timeslot to form at least one traffic flow corresponding to a connection or call; analyzing the at least one traffic flow to select at least one suspicious target traffic flow; and outputting the at least one selected suspicious target flow.
Public/Granted literature
- US20170339108A1 Network Traffic Analysis to Enhance Rule-Based Network Security Public/Granted day:2017-11-23
Information query