Network Forensic Methods

The network forensic system addresses the challenge of diverse hacking attacks by implementing high-performance packet stream storage and real-time index processing, enabling rapid analysis and detection of hacking incidents without data loss and high costs.

JP7755633B2Active Publication Date: 2025-10-16QUAD MINERS CO LTD
View PDF 12 Cites 0 Cited by

Patent Information

Application Number
JP2023198503
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2019-06-20
Filing Date
2023-11-22
Publication Date
2025-10-16
Estimated Expiration
2039-07-18

AI Technical Summary

Technical Problem

Existing network security systems struggle with diverse hacking attacks, requiring rapid packet analysis and storage of ultra-high-speed, large-volume traffic without data loss, while conventional methods incur high costs due to the need for high-speed storage.

Method used

A high-performance packet stream storage system with distributed storage and processing, pattern-based index processing, and scenario-centric real-time attack detection, enabling ultra-high-speed packet storage and analysis without data loss and accommodating various attack scenarios.

Benefits of technology

The system provides rapid analysis and response to hacking incidents with real-time index processing, user-defined index data generation, and scenario-centric detection, classifying data by hacking scenario for quick incident analysis.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007755633000001
    Figure 0007755633000001
  • Figure 0007755633000002
    Figure 0007755633000002
  • Figure 0007755633000003
    Figure 0007755633000003
Patent Text Reader

Abstract

To provide a high-performance packet stream storage system with a high-speed data storage technology for quickly analyzing and responding to a hacking accident on the basis of ultra-high-speed, large-capacity data, and a high-performance packet stream storage method using the same.SOLUTION: A method for storing a high-performance packet stream using a high-performance packet stream storage system includes a step (a) of collecting raw packet data from data traffic transmitted over a network, a step (b) of recording the collected raw packet data in a memory, a step (c) of extracting metadata from the collected raw packet data and recording it in the memory, and a step (d) of storing the raw packet data and the metadata from the memory into a storage unit.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a network forensic system and a network forensic method using the same, and more particularly to a high-performance packet stream storage system and method, a pattern-based index processing system and method, and a scenario-centric real-time attack detection system and method, all of which are realized by the network forensic system and method. [Background technology]

[0002] In an age where not only IT devices but also homes, cars, cities, factories, and everything else are connected by ultra-high-speed networks, the impact of hacking or cyberterrorism is beyond imagination. As a result, many companies are devoting significant efforts to strengthening network security.

[0003] However, hacking attacks are becoming more diverse every day, and the difficulty of recognizing them is gradually increasing. This has led to a demand for technology that can grasp the overall flow of a hacking attack and quickly recognize hacker attacks by performing rapid packet analysis.

[0004] 99% of hacking attempts result in a breach within a few days, and 85% of these result in data leakage. Since it takes more than a few weeks to detect these 85% of hacking incidents, many studies have been conducted on how to shorten the time it takes hackers to recognize an attack through rapid packet analysis.

[0005] In addition, storing and analyzing ultra-high-speed, large-volume traffic requires high-speed I / O performance, and using high-speed storage for this purpose increases product costs.There is also a need for technology that can collect and store packets from ultra-high-speed, large-volume traffic without data loss and analyze the data to respond to various attack scenarios and environments, even without using high-speed storage. [Prior art documents] [Patent documents]

[0006] [Patent Document 1] Japanese Patent Application Laid-Open No. 2008-271416 Summary of the Invention [Problem to be solved by the invention]

[0007] The technical problem to be solved by the high-performance packet stream storage system and high-performance packet stream storage method realized by the network forensic system and method according to the technical concept of the present invention is to provide a high-performance packet stream storage system having high-speed data storage technology for rapid analysis and response to hacking incidents based on ultra-high-speed, large-volume data, and a high-performance packet stream storage method using the same.

[0008] The technical problem to be solved by the pattern-based index processing system and pattern-based index processing method realized by the network forensic system and method according to the technical idea of ​​the present invention is to provide a pattern-based index processing system and pattern-based index processing method that can perform index processing in real time.

[0009] Another technical problem that the pattern-based index processing system and pattern-based index processing method realized by the network forensic system and method according to the technical idea of ​​the present invention aims to solve is to provide a pattern-based index processing system and pattern-based index processing method that can generate user-defined index data to accommodate various attack scenarios and environments.

[0010] Another technical problem to be solved by the pattern-based index processing system and pattern-based index processing method realized by the network forensic system and method according to the technical idea of ​​the present invention is to provide a pattern-based index processing system and pattern-based index processing method that allows a user to specify and re-index data at a point in time of interest.

[0011] Another technical problem to be solved by the pattern-based index processing system and pattern-based index processing method realized by the network forensic system and method according to the technical idea of ​​the present invention is to provide a pattern-based index processing system and pattern-based index processing method that can classify applications, metadata, and user-defined patterns for scenario analysis.

[0012] The technical problem that the scenario-centric real-time attack detection system and scenario-centric real-time attack detection method realized by the network forensic system and method according to the technical idea of ​​the present invention aims to solve is to provide a scenario-centric real-time attack detection system and scenario-centric real-time attack detection method that can classify data by hacking scenario through the index integration process and quickly analyze hacking incidents.

[0013] Another technical problem that the scenario-centric real-time attack detection system and scenario-centric real-time attack detection method realized by the network forensic system and method according to the technical concept of the present invention aims to solve is to provide a scenario-centric real-time attack detection system and scenario-centric real-time attack detection method that can classify applications, metadata, and user-defined patterns for scenario analysis.

[0014] The technical problems that the network forensic system and the network forensic method using the same based on the technical idea of ​​the present invention aim to solve are not limited to the above-mentioned technical problems, and other technical problems not mentioned above should be clearly understood by those skilled in the art from the following description. [Means for solving the problem]

[0015] In one embodiment according to the technical concept of the present invention, a method for storing a high-performance packet stream by a high-performance packet stream storage system may include the steps of: (a) collecting original packet data from data traffic transmitted over a network; (b) recording the collected original packet data in a memory; (c) extracting metadata from the collected original packet data and recording it in a memory; and (d) storing the original packet data and the metadata from the memory to a storage unit.

[0016] The high performance packet stream storage method may further include filtering exception information from the collected original packet data to exclude it from being recorded in memory.

[0017] The storage unit may include a local disk, and step (d) may include storing the original packet data and the metadata directly from the memory to the local disk when the network speed is below a predetermined standard.

[0018] The storage unit may include a plurality of extended nodes, and step (d) may include a step of distributing and storing the original packet data and the metadata from the memory to the plurality of extended nodes when the network speed exceeds a predetermined standard.

[0019] The high performance packet stream storage method may further include, after step (d), returning the memory in which the original packet data and the metadata are recorded.

[0020] The step (a) may include the step of reserving additional memory for the excess amount of original packet data when the amount of collected packets exceeds the collection setting value.

[0021] Step (c) may include a step of recording the collected original packet data and the extracted metadata in the memory for a predetermined recording period, and then storing the data from the memory in the storage unit.

[0022] According to one embodiment of the technical concept of the present invention, a high-performance packet stream storage system may include a data management module that collects original packet data from data traffic transmitted over a network and extracts metadata from the collected original packet data; a memory unit in which the original packet data and the metadata are recorded; a storage unit in which the original packet data and the metadata are stored and organized into a database; a storage management module that stores the original packet data and the metadata from the memory unit to the storage unit; and a memory management module that returns the memory area of ​​the memory unit in which the original packet data and the metadata were recorded after the original packet data and the metadata have been stored from the memory unit to the storage unit.

[0023] The storage unit includes a local disk, and the storage management module includes a disk management module, and when the network speed is below a predetermined standard, the disk management module can store the original packet data and the metadata directly from the memory unit to the local disk.

[0024] The storage unit includes a plurality of extended nodes, and the storage management module includes a data distribution management module, and when the network speed exceeds a predetermined standard, the data distribution management module can distribute and store the original packet data and the metadata from the memory unit to the extended nodes.

[0025] According to one embodiment of the technical concept of the present invention, a method for processing a pattern-based index using a pattern-based index processing system may include the steps of: (a) recombining packet data; (b) performing application analysis on the recombined packet data; and (c) extracting and indexing metadata of the recombined packet data.

[0026] Step (a) may include reassembling the packet data based on TCP (Transmission Control Protocol) header information.

[0027] Step (b) may include determining an application for the reassembled packet data based on RFC (Request for Comments) standards.

[0028] If the reassembled packet data is data generated by an application of the RFC standard, in step (c), extracting metadata from the reassembled packet data based on the RFC standard. may include:

[0029] Step (b) may include determining an application for the reassembled packet data based on a user-defined standard.

[0030] If the reassembled packet data is data generated by application of a user-defined standard, step (c) may include extracting metadata from the reassembled packet data based on the user-defined standard.

[0031] In the pattern-based index processing method, step (a) may include the steps of collecting packet data from data traffic transmitted over a network, recording the collected packet data in a memory for a predetermined recording period, extracting metadata from the collected packet data and recording it in a memory for the predetermined recording period, storing the recorded packet data and the metadata from the memory to a storage unit after the predetermined recording period has elapsed, and rearranging the stored packet data in units of the predetermined recording period.

[0032] The step (a) may include a step of returning the memory in which the packet data and the metadata are recorded after the storing step in the storage unit.

[0033] The storage unit may include a local disk, and step (a) may include a step of storing the packet data and the metadata directly from the memory to the local disk when the network speed is below a predetermined standard.

[0034] The storage unit may include a plurality of extended nodes, and step (a) may include a step of distributing and storing the packet data and the metadata from the memory to the plurality of extended nodes when the network speed exceeds a predetermined standard.

[0035] According to one embodiment of the technical concept of the present invention, a scenario-centric real-time attack detection method using a scenario-centric real-time attack detection system may include the steps of: (a) forming a scenario to be applied to indexed metadata; (b) extracting and indexing metadata from packet data; and (c) detecting indexed metadata corresponding to the scenario.

[0036] Step (a) may include forming a single detection scenario to be applied to the indexed metadata, and combining a plurality of single detection scenarios to form a multi-detection scenario.

[0037] A single detection scenario includes one or more conditions for fulfillment, and the scenario is determined to be fulfilled when all of the conditions for fulfillment are met. The conditions for fulfillment may include index type and pattern information.

[0038] A multiple detection scenario can be determined to be true when two or more single detection scenarios are all true and a common condition is met.

[0039] The step (b) may include a step of rearranging the packet data stored in a predetermined recording cycle based on TCP (Transmission Control Protocol) header information, and a step of extracting and indexing metadata from the rearranged packet data.

[0040] The step (b) may include, before the step of recombining the packet data, a step of collecting packet data from data traffic transmitted over a network; a step of recording the collected packet data in a memory for a predetermined recording period; a step of extracting metadata from the collected packet data and recording the metadata in a memory for the predetermined recording period; and a step of storing the recorded packet data and the metadata from the memory in a storage unit after the predetermined recording period has elapsed.

[0041] The step (b) may include a step of returning the memory in which the packet data and the metadata are recorded after the storing step in the storage unit.

[0042] The storage unit may include a local disk, and step (b) may include storing the packet data and the metadata directly from the memory to the local disk when the network speed is below a predetermined standard.

[0043] The storage unit may include a plurality of extended nodes, and step (b) may include a step of distributing and storing the packet data and the metadata from the memory to the plurality of extended nodes when the network speed exceeds a predetermined standard.

[0044] The scenario-centric real-time attack detection method may further include, before step (b), performing application analysis on the packet data. [Effects of the Invention]

[0045] The high performance packet stream storage system and method implemented by the network forensic system and method according to the embodiment of the technical concept of the present invention have the following advantages.

[0046] (1) A sequential storage database based on a partition key can be provided as a high-performance packet stream storage technology for rapid analysis and response to hacking incidents.

[0047] (2) It is possible to provide a technology that can store packet streams without data loss in ultra-high speed networks, extract summarized data from them, and create a database.

[0048] (3) It is possible to provide a technology for distributed storage and processing of packets that enables ultra-high speed and large volume traffic to be stored without using high speed storage.

[0049] The pattern-based index processing system and pattern-based index processing method realized by the network forensic system and method according to the embodiment of the technical concept of the present invention have the following advantages.

[0050] (1) It is possible to provide a pattern-based index processing technique that can perform index processing in real time.

[0051] (2) It is possible to provide a technology that can generate user-defined index data to accommodate various attack scenarios and environments.

[0052] (3) It is possible to provide a technology that allows users to specify and re-index data at a point in time that is problematic.

[0053] (4) It is possible to provide technology that can classify applications, metadata, and user-defined patterns for scenario analysis.

[0054] The scenario-centric real-time attack detection system and scenario-centric real-time attack detection method realized by the network forensic system and method according to the embodiment of the technical concept of the present invention have the following advantages.

[0055] (1) It is possible to provide a scenario-centric real-time attack detection technology that can quickly analyze hacking incidents by classifying data by hacking scenario through the index integration process.

[0056] (2) It can provide a scenario-centric real-time attack detection technology that can classify applications, metadata, and user-defined patterns for scenario analysis.

[0057] However, the effects that can be achieved by the high-performance packet stream storage system and high-performance packet stream storage method according to one embodiment of the present invention are not limited to the effects described above, and other effects not mentioned will be clearly understood by those skilled in the art from the following description. [Brief explanation of the drawings]

[0058] In order to more fully understand the drawings referred to herein, a brief description of each drawing is provided.

[0059] [Figure 1] 1 is a schematic flowchart of a method for improving hacking attack recognition and cause analysis performance using a network forensic system and method according to an embodiment of the present invention. [Figure 2] 1 is a diagram illustrating a high performance packet stream storage method according to an embodiment of the present invention in comparison with a conventional packet stream storage method; [Figure 3] 1 is a schematic diagram of a high performance packet stream storage system according to an embodiment of the present invention; [Figure 4] 1 is a diagram specifically illustrating a method for storing a high-performance packet stream according to an embodiment of the present invention. [Figure 5] 1 is a diagram illustrating a method for processing a pattern-based index according to an embodiment of the present invention in comparison with a conventional method for processing a pattern-based index; [Figure 6] FIG. 2 is a diagram illustrating a method for processing a pattern-based index according to an embodiment of the present invention. [Figure 7] 1 is a flow chart that outlines a method for processing a pattern-based index according to an embodiment of the present invention. [Figure 8] 1 is a diagram illustrating a scenario-centric real-time attack detection method according to an embodiment of the present invention in comparison with a conventional attack detection method; [Figure 9] 1 is a diagram illustrating a scenario-centric real-time attack detection method according to an embodiment of the present invention. [Figure 10] FIG. 2 is a diagram illustrating steps in which a single detection scenario is used in a scenario-centric real-time attack detection system according to one embodiment of the present invention. [Figure 11]FIG. 1 is a diagram illustrating steps in which multiple detection scenarios are used in a scenario-centric real-time attack detection system according to one embodiment of the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0060] Although the present invention can be modified in various ways and can have various embodiments, specific embodiments are illustrated and described in detail herein. However, this is not intended to limit the present invention to the specific embodiments, and it should be understood that the present invention includes all modifications, equivalents, and alternatives included within the spirit and technical scope of the present invention.

[0061] In describing the present invention, detailed descriptions of related publicly known technologies will be omitted if it is deemed that such descriptions may unnecessarily obscure the gist of the present invention. Note that numbers used in this specification (e.g., first, second, etc.) are merely identification symbols for distinguishing one component from another.

[0062] Furthermore, in this specification, when a component is referred to as being "coupled" or "connected" to another component, it should be understood that the component may be directly coupled to or connected to the other component, but unless otherwise specified, they may also be coupled to or connected via other components.

[0063] Furthermore, a component expressed as a "part" in this specification may be two or more components combined into one component, or one component may be divided into two or more components according to further subdivided functions. It goes without saying that each of the components described below may perform some or all of the functions of other components in addition to its own main function, and that some of the main functions of each component may be performed by other components.

[0064] Hereinafter, embodiments according to the technical concept of the present invention will be described in detail one by one.

[0065] FIG. 1 is a schematic flowchart of a method for improving hacking attack recognition and cause analysis performance using a network forensic system and method according to an embodiment of the present invention.

[0066] Hacking attack methods are becoming more diverse and complex, which means packet analysis and recognition takes a lot of time and money. To solve this, three problems need to be solved:

[0067] First, as attacks become more complex, packet analysis becomes more difficult. Second, it is necessary to analyze not only event logs at the time of the incident but also a large volume of packets from the preparatory actions to the attack itself. Third, the difficulty of collecting and analyzing data from ultra-high-speed networks needs to be resolved.

[0068] For this reason, high-performance packet stream storage technology, pattern-based index processing technology, and scenario-centric real-time attack detection technology have been developed, as shown in Figure 1.

[0069] FIG. 2 is a diagram illustrating a high-performance packet stream storage method according to an embodiment of the present invention in comparison with a conventional packet stream storage method.

[0070] Conventional packet storage methods simply collect packets in real time and store them directly on a local disk, but storing ultra-high-speed, large-volume traffic such as 10 Gbps requires high-speed I / O performance, necessitating the use of high-speed storage, which increases the product cost of the security system.

[0071] To solve these problems, a high-performance packet stream storage system and a high-performance packet stream storage method using the same according to one embodiment of the present invention perform distributed storage processing to achieve ultra-high-speed packet storage and large-capacity data processing without data loss.

[0072] Figure 3 is a diagram illustrating a system for storing high performance packet streams according to an embodiment of the present invention, and Figure 4 is a diagram illustrating a method for storing high performance packet streams according to an embodiment of the present invention.

[0073] A high performance packet stream storage system 100 according to one embodiment of the present invention may include a data access module (DAM) 110, a memory unit 120, a storage unit 130, a storage management module 140, and a memory management module (DMM) 150.

[0074] The storage unit 130 may include a local disk 132 and / or multiple remotely located extended nodes 134, and the storage management module 140 may include a disk management module (DIM; Disk Interface Module) 142 and / or a data distribution management module (DDM; Data Distributed Module) 144.

[0075] The network connects an intranet and the Internet, and large volumes of data are transmitted at extremely high speeds through the network. The data management module 110 is a device that collects, analyzes, and stores network packet data, and can collect original packet data from data traffic transmitted through the network in real time (S1110).

[0076] The data management module 110 checks whether the amount of collected packets exceeds the collection setting value (S1120), and if the amount of collected packets is equal to or less than the collection setting value, it can immediately record the original packet data collected in real time in a memory area reserved in the memory unit 120 (S1130).

[0077] If the amount of packets collected by the data management module 110 exceeds the collection setting value, the data management module 110 can preliminarily reserve additional memory in the memory unit 120 for the excess amount of original packet data and readjust the collection setting value (S1140).

[0078] Additionally, the data management module 110 may extract metadata from the collected original packet data and record the extracted metadata in a memory area reserved in the memory unit 120. The metadata may include a source IP, a source port, a destination IP, a destination port, a protocol, etc.

[0079] The data management module 110 may perform packet IP / port analysis (S1150) and TCP / UDP packet analysis (S1160), but is not limited thereto, and may perform only one of packet IP / port analysis and TCP / UDP packet analysis.

[0080] The data management module 110 may filter the exception information from the extracted metadata and exclude the original packet data corresponding to the exception information from being recorded in the memory (S1170). Here, the exception information may be personal information, information transmitted by a specific person, information related to a specific IP, etc.

[0081] The collected original packet data and extracted metadata may be recorded in the memory area of ​​memory unit 120 for a predetermined recording period (S1180), and then stored in storage unit 130 by storage management module 140. For example, the collected original packet data and extracted metadata may be recorded for one minute in the memory of memory unit 120, and the original packet data and metadata recorded for one minute in this manner are combined and prepared to be stored in storage unit 130 as a database in one-minute units (S1190). Storage management module 140 can store the original packet data and metadata from memory unit 120 to storage unit 130 and create a database.

[0082] Storage management module 140 selects whether to store the original packet data and metadata on local disk 132 or to store them in a distributed manner across extended nodes 134 (S1200).

[0083] When the network speed is equal to or lower than a predetermined standard, the disk management module 142 can directly store the original packet data and metadata from the memory unit 120 onto the local disk 132 (S1210). The disk management module 142 directly accesses the local disk 132 without going through the OS, and therefore can most quickly store the original packet data and metadata onto the local disk 142. The original packet data and metadata are recorded onto the local disk 132 at a predetermined recording cycle (for example, every minute).

[0084] If the network speed exceeds a predetermined standard, the data distribution management module 144 can distribute and store the original packet data and metadata from the memory unit 120 to the extended nodes 134 (S1220). The distributed storage method is a method in which large-scale structured data is divided into multiple parts and then stored and managed in a distributed manner, and any known distributed storage method may be used.

[0085] With this configuration, even if the network speed becomes extremely high, all data can be stored without any loss, without increasing the performance of the hardware in the storage section.

[0086] As shown in FIG. 4, the original packet data and metadata are organized into a database and stored in storage unit 130. The metadata is used as information summarizing the packet data for quick information retrieval of the data, and the original packet data is used as raw data for checking whether or not it has been hacked.

[0087] The memory management module 150 manages the memory area used for storing and analyzing packets, and after the original packet data and metadata are stored from the memory unit 120 to the storage unit 130, the memory management module 150 can return the memory area of ​​the memory unit 120 in which the original packet data and metadata were recorded (S1230).

[0088] FIG. 5 is a diagram illustrating a pattern-based index processing method according to an embodiment of the present invention in comparison with a conventional pattern-based index processing method.

[0089] The conventional indexing method was to index a large amount of packet data for a specific pattern at a specific time. In other words, the application analysis basic module analyzed the large amount of packet data, and the metadata extraction module extracted metadata based on the analyzed data.

[0090] In contrast, according to a pattern-based index processing method of one embodiment of the present invention, user-defined index data can be generated to accommodate various attack scenarios and environments, and index processing can provide not only real-time index processing but also the ability for users to specify and re-index data at problematic points in time.

[0091] That is, according to the pattern-based index processing method of one embodiment of the present invention, a user-defined pattern-based index management interface can index user patterns into original packet data, application patterns can be added to the application basic module, and metadata patterns can be added to the metadata extraction module. According to the pattern-based index processing method of one embodiment of the present invention, in addition to the conventional method of indexing predetermined patterns at predetermined times, required patterns can be indexed at required times to analyze original packet data stored in a storage unit.

[0092] Figure 6 is a schematic diagram illustrating a method for processing a pattern-based index according to an embodiment of the present invention. Figure 7 is a flowchart illustrating a method for processing a pattern-based index according to an embodiment of the present invention.

[0093] According to a method for processing a pattern-based index according to an embodiment of the present invention, various scenario-based patterns can be defined, and session-based packets can be classified and redefined according to the patterns to analyze various hacking attempts.

[0094] A pattern-based index processing system according to an embodiment of the present invention may include a data recombination module, an application analysis module, and a metadata extraction module.

[0095] The original packet data stored in the storage unit 130 at a predetermined recording cycle may be recombined by a recombination module for indexing purposes. The recombination module recombines the original packet data stored in the storage unit 130 based on TCP (Transmission Control Protocol) header information of the original packet data stored in the storage unit 130 (S2110).

[0096] Based on the original packet data recombined in this way, the application analysis module starts analyzing the application (S2120). The application analysis module determines what type of application generated the original packet data.

[0097] The application analysis module can determine the application based on the RFC standard for the reassembled original packet data (S2130), and can use user-defined rules to determine applications not defined in the RFC standard (S2140).

[0098] When the application that generated the recombined original packet data is identified in this manner (S2150), the metadata extraction module can extract metadata from the recombined original packet data (S2160). If the original packet data was generated by an application defined in the RFC standard, metadata can be extracted based on the RFC standard (S2170). If the original packet data was generated by an application not defined in the RFC standard, metadata can be extracted according to user-defined rules (S2180).

[0099] The user-defined rules used by the application analysis module to determine applications and the user-defined rules used by the metadata extraction module to extract metadata may be defined by a pattern-based user-defined index management interface.

[0100] The metadata extraction module finally indexes the extracted metadata through an indexing operation (S2180).

[0101] As shown in FIG. 6, metadata may be extracted and indexed for each application. For example, if the application is determined to be HTTP, the extracted metadata may be indexed as a URL, web information, attachments, etc.; if the application is determined to be FTP, the extracted metadata may be indexed as a login ID, server ID, attachments, etc.; if the application is determined to be SMTP, the extracted metadata may be indexed as a sender, recipient, attachments, etc.; if the application is determined to be DNS, the extracted metadata may be indexed as a domain query, server query, etc.; if the application is determined to be SSL, the extracted metadata may be indexed as a server certificate, URL, service information, etc. Furthermore, if the application is determined to be an application defined by a user-defined rule, the extracted metadata may be indexed in a format defined accordingly.

[0102] The metadata extraction module can combine various metadata indexes into one application index.

[0103] FIG. 8 is a diagram illustrating a scenario-centric real-time attack detection method according to an embodiment of the present invention in comparison with a conventional attack detection method.

[0104] Previously, data analysis was performed by repeatedly searching for different situations and conditions. For example, origin / destination information was searched for 108 different conditions, such as web host address, application, origin / destination country, web meta-method, web meta-return code, web meta-path, web meta-X forwarded, connection duration, uploaded / downloaded files, number of packets, and protocol type.

[0105] In contrast, a scenario-centric real-time attack detection method according to an embodiment of the present invention can quickly analyze hacking incidents by classifying data by hacking scenario through an index integration process. That is, a method is used in which multiple scenarios are created in advance by integrating pattern-based index data (e.g., origin / destination, nationality information, connection duration, attachment type, email sender, etc.) and performing pattern modeling on continuously occurring hacking incident patterns, and only raw packet data that allows the scenarios to be established is checked.

[0106] FIG. 9 is a diagram illustrating a scenario-centric real-time attack detection method according to an embodiment of the present invention.

[0107] According to a scenario-centric real-time attack detection method using a scenario-centric real-time attack detection system according to one embodiment of the present invention, first, a scenario generation module performs a step of forming a scenario to be applied to indexed metadata, a metadata extraction module performs a step of extracting and indexing metadata from original packet data, and a metadata detection module performs a step of detecting indexed metadata corresponding to the scenario.

[0108] Here, the scenario may include a single detection scenario applied to the indexed metadata and a multiple detection scenario that combines multiple single detection scenarios. Also, in the step of the metadata extraction module extracting and indexing metadata from packet data, the analysis of an application and the extraction and indexing of metadata based thereon have been described above, but it is not necessarily necessary to extract and index metadata based on the analysis of an application, and the analysis of an application may not be performed.

[0109] A single detection scenario includes one or more conditions, and if all of the conditions are met, the metadata and corresponding packet data determine that the scenario is met. The conditions may include index type and pattern information. Examples of index type and pattern information are described below with reference to Figures 10 and 11.

[0110] As shown in Figure 9, a scenario-centric real-time attack detection system can be used to generate a single detection scenario by integrating the metadata of the generated index (e.g., server nation information, connection duration, web attachment type, web attachment direction, application type, email sender, email body, origin IP, destination IP, web URL address, etc.).

[0111] For example, the single detection scenario may include a data leakage scenario, a virus download scenario, a C&C connection scenario, an insider information leakage scenario, and the like.

[0112] The data leakage scenario may be configured with indexes of web attachment type and web attachment direction. The web attachment type may be defined as pdf, hwp, docx, etc., and the web attachment direction may be defined as upload.

[0113] The virus download scenario may be configured with indexes of the type of web attachment and the direction of the web attachment. The type of web attachment may be defined as exe, dll, etc., and the direction of the web attachment may be defined as download.

[0114] The C&C connection scenario may be configured with indexes such as application type and server country information. The application type may be defined as IRC, HTTP, etc., and the server country information may be defined as China, Russia, etc.

[0115] An insider information leakage scenario may be configured with indexes of email senders and email bodies. The email sender may be defined as a server in a specific domain, and the email body may be defined as content containing the words "confidential" or "internal use only."

[0116] The scenario generation module can combine multiple single detection scenarios to generate multiple detection scenarios, such as an APT attack scenario, a confidential information leak scenario, etc.

[0117] The APT attack scenario can be realized when the virus download scenario, C&C connection scenario, and data leakage scenario are all realized, and the confidential information leakage scenario can be realized when both the insider information leakage scenario and the data leakage scenario are realized.

[0118] 10 is a diagram illustrating steps for using a single detection scenario in a scenario-centric real-time attack detection system according to an embodiment of the present invention. FIG. 11 is a diagram illustrating steps for using multiple detection scenarios in a scenario-centric real-time attack detection system according to an embodiment of the present invention.

[0119] For example, as shown in FIG. 10, rule ID 1 in a single detection scenario can have two conditions. In the case of condition 1, the index type (Index Type) may be set as HTTP URL, and the pattern information (Rule Pattern) may be set as www.dropbox.com. In the case of condition 2, the index type may be set as HTTP Upload Type, and the pattern information may be set as docx. In this case, when connecting to www.dropbox.com (condition 1 is satisfied) and uploading a file with the docx extension (condition 2 is satisfied), it can be detected that an attachment has been uploaded to a web hard drive.

[0120] Also, rule ID 2 of a single detection scenario can have only one condition. In the case of condition 1, the index type may be set as an SSL (Secure Sockets Layer) domain, and the pattern information (Rule Pattern) may be set as saramin.co.kr. In this case, when connecting to the job-changing website saramin.co.kr as an SSL domain, it can be detected that an attempt to connect to a job-changing website has been made.

[0121] A multiple detection scenario can be determined to be established when two or more single detection scenarios are all established and the common conditions of the multiple detection scenarios are established.

[0122] For example, as shown in Figure 11, rule ID3 of the multiple detection scenario satisfies rule ID1 and rule ID2 of the single detection scenario, but if the source IP (SIP; Source IP) of the packet data that satisfies the common condition of rule ID1 and rule ID2 is the same (192.168.10.147 in Figure 11), it is determined that the scenario is established, and in this case, it can be detected that an act of confidential information leakage has occurred.

[0123] This method allows for the creation of various scenarios, enabling faster and more accurate detection and analysis of suspected hacking data, and enabling attacks to be detected quickly.

[0124] The functional operations described herein and embodiments of the present subject matter, including the structures disclosed herein and their structural equivalents, can be implemented in digital electronic circuitry, or in computer software, firmware, or hardware, or in combinations of one or more of these.

[0125] Embodiments of the subject matter described herein may be implemented as one or more computer program products, i.e., one or more modules of computer program instructions encoded on a tangible program medium for execution by or to control the operation of a data processing apparatus. The tangible program medium may be an electrical waveform signal or a computer-readable medium. An electrical waveform signal is an artificially generated signal, such as a machine-generated electrical, optical, or electromagnetic signal, that is generated to encode information for transmission to a suitable receiver device for execution by a computer. The computer-readable medium may be a machine-readable storage device, a machine-readable storage substrate, a memory device, a combination of material affecting a machine-readable electrical waveform signal, or a combination of any one or more of these.

[0126] Computer programs (also referred to as programs, software, applications, software applications, scripts, or code) can be written in any form of programming language, including compiled or interpreted languages, and a priori or procedural languages, and can be deployed in any form, including as stand-alone programs or as modules, components, subroutines, or other units suitable for use in a computing environment.

[0127] A computer program does not necessarily correspond to a file in a file system: a program can be stored in a single file that is provided to the program upon request, or in multiple interacting files (e.g., a file that contains one or more modules, subprograms, or portions of code), or even part of a file that holds other programs or data (e.g., one or more scripts stored in a markup language document).

[0128] A computer program may be deployed to be executed on one computer or multiple computers that are located at one site or distributed across multiple sites and interconnected by a communications network.

[0129] Furthermore, the logic flow and structural block diagrams set forth herein describe corresponding functions supported by the disclosed structural means, corresponding acts supported by steps, and / or particular methods, and may be used to construct corresponding software structures and algorithms and their equivalents.

[0130] The processes and logic flows described herein may be implemented by one or more programmable processors executing one or more computer programs to perform functions by operating on input data and generating output.

[0131] Processors suitable for the execution of a computer program include, by way of example, both general and special purpose microprocessors, and any one or more processors of any kind of digital computer. Generally, a processor receives instructions and data from a read-only memory or a random access memory or both.

[0132] The essential elements of a computer are one or more memory devices for storing instructions and data, and a processor for executing instructions. A computer also typically includes one or more mass storage devices, such as magnetic, magneto-optical, or optical disks, for storing data, and is operatively coupled to receive data from, transmit data to, or transmit data to and from the one or more mass storage devices. However, a computer need not have such devices.

[0133] This description of the technology sets forth the best mode of the invention and provides examples for explaining the invention and for those skilled in the art for making and using the invention. The specification so written is not intended to limit the invention to the specific terms set forth therein.

[0134] Therefore, although the present invention has been described in detail with reference to the above examples, those skilled in the art can make modifications, changes, and variations to the examples without departing from the scope of the present invention. In short, it is clear that in order to achieve the intended effects of the present invention, all functional blocks shown in the drawings need not be separately included or all sequences shown in the drawings need not be followed exactly, and that the technical scope of the present invention as defined in the claims can be achieved in any manner regardless of the above. [Explanation of symbols]

[0135] 110 Data Management Module 120 Memory section 130 Storage area 140 Storage Management Module 150 Memory Management Module

Claims

1. A method for processing an index, (a) recombining original packet data based on TCP (Transmission Control Protocol) header information; (b) performing application analysis on the recombined original packet data; (c) extracting and indexing metadata from application data after the application is identified through the application analysis; The step (a) collecting original packet data from data traffic transmitted over a network; recording the collected original packet data in a memory for a predetermined recording period; extracting metadata from the collected original packet data and recording the metadata in a memory during the predetermined recording period; storing the recorded original packet data and the metadata from the memory into a storage unit after the predetermined recording period has elapsed; a step of rearranging the original packet data stored in the predetermined recording cycle unit; Including, In the step (b), determining an application for the reassembled original packet data based on user-defined rules; The step (c) an index processing method characterized by: when it is confirmed that the application is HTTP, extracting and indexing at least one of a URL, web information, and attached file as the metadata; when it is confirmed that the application is FTP, extracting and indexing at least one of a login ID, a server ID, and attached file as the metadata; when it is confirmed that the application is SMTP, extracting and indexing at least one of a sender, a recipient, and attached file as the metadata; when it is confirmed that the application is DNS, extracting and indexing at least one of a domain query and a server query as the metadata; when it is confirmed that the application is SSL, extracting and indexing at least one of a server certificate, a URL, and service information as the metadata; and when it is confirmed that the application is an application defined by a user-defined rule, extracting and indexing the metadata in a form defined in accordance with the user-defined rule.

2. The step (a) 2. The index processing method according to claim 1, further comprising a step of returning the memory in which the original packet data and the metadata are recorded after the storing step in the storage unit.

3. the storage unit includes a local disk; The step (a) 2. The index processing method of claim 1, further comprising the step of storing the original packet data and the metadata directly from the memory to the local disk when the network speed is below a predetermined standard.

4. the storage unit includes a plurality of extended nodes; The step (a) 2. The index processing method according to claim 1, further comprising the step of distributing and storing the original packet data and the metadata from the memory to a plurality of extended nodes when the network speed exceeds a predetermined standard.

Citation Information

Patent Citations

  • Communication system, server, communication method and computer program

    JP2007200209A

  • Network forensic system, network monitoring method, and mac address sampling method

    JP2008271416A

  • Information processor, information processing system, message processing method, and message processing program

    JP2012069057A

  • Monitoring data loss in partial data streams

    JP2014501066A

  • System and method for extracting and storing metadata for network communication analysis

    JP2016513944A