Abnormality detection system and method based on protocol analysis
A protocol analysis and anomaly detection technology, which is applied in the field of network security, can solve the problems of affecting identification efficiency, large bottlenecks in processing performance, difficulty in realizing application layer protocol identification and processing, etc., and achieve the effect of simplifying processing intensity
- Summary
- Abstract
- Description
- Claims
- Application Information
AI Technical Summary
Problems solved by technology
Method used
Image
Examples
Embodiment Construction
[0020] In order to make the purpose, content, and advantages of the present invention clearer, the specific implementation manners of the present invention will be further described in detail below in conjunction with the accompanying drawings and embodiments.
[0021] figure 1 Shown is the block diagram of the anomaly detection system based on the protocol analysis of the present invention, as figure 1 As shown, the anomaly detection system based on protocol analysis of the present invention includes: data capture module 1, data state recording module 2, data analysis module 3, rule detection module 4, wherein data analysis module 3 includes data analysis sub-module 31 and protocol attribute analysis Submodule 32.
[0022] Such as figure 1 As shown, the data capture module 1 completes the cache of Ethernet data and sends it to the data status record module 2 for historical status record matching; the data status record module 2 completes the comparison between the event dat...
PUM
Login to View More Abstract
Description
Claims
Application Information
Login to View More 


