发明授权
- 专利标题: Methods and systems to detect an evasion attack
- 专利标题(中): 检测逃避攻击的方法和系统
-
申请号: US11552025申请日: 2006-10-23
-
公开(公告)号: US08613088B2公开(公告)日: 2013-12-17
- 发明人: George Varghese , Flavio Giovanni Bonomi , John Andrew Fingerhut
- 申请人: George Varghese , Flavio Giovanni Bonomi , John Andrew Fingerhut
- 申请人地址: US CA San Jose
- 专利权人: Cisco Technology, Inc.
- 当前专利权人: Cisco Technology, Inc.
- 当前专利权人地址: US CA San Jose
- 代理机构: Schwegman Lundberg & Woessner, P.A.
- 主分类号: G06F12/14
- IPC分类号: G06F12/14
摘要:
A method and system to detect an evasion attack are provided. The system may include a repository to store signature fragments that together constitute an attack signature, an interceptor to intercept a data packet associated with a network connection, a string-matching module to determine whether the payload of the data packet includes any of the stored signature fragments thereby identifying a match, a responder to perform a prevention action in response to the match, and a detector to detect that a size of the data packet is less than a size threshold. The system may further include a state machine to commence maintaining a state for the network connection in response to the detector determining that the size of the data packet is less than the size threshold.
公开/授权文献
- US20070192861A1 METHODS AND SYSTEMS TO DETECT AN EVASION ATTACK 公开/授权日:2007-08-16
信息查询