KR101074597B1 - 가상 웹서버 기반의 침입 유도 시스템 및 그 방법 - Google Patents
가상 웹서버 기반의 침입 유도 시스템 및 그 방법 Download PDFInfo
- Publication number
- KR101074597B1 KR101074597B1 KR1020040074724A KR20040074724A KR101074597B1 KR 101074597 B1 KR101074597 B1 KR 101074597B1 KR 1020040074724 A KR1020040074724 A KR 1020040074724A KR 20040074724 A KR20040074724 A KR 20040074724A KR 101074597 B1 KR101074597 B1 KR 101074597B1
- Authority
- KR
- South Korea
- Prior art keywords
- intrusion
- request message
- web
- web server
- alert
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Expired - Fee Related
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1441—Countermeasures against malicious traffic
- H04L63/1466—Active attacks involving interception, injection, modification, spoofing of data unit addresses, e.g. hijacking, packet injection or TCP sequence number attacks
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1408—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L67/00—Network arrangements or protocols for supporting network services or applications
- H04L67/01—Protocols
- H04L67/02—Protocols based on web technology, e.g. hypertext transfer protocol [HTTP]
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
- Computer And Data Communications (AREA)
Abstract
Description
Claims (6)
- HTTP 표준 프로토콜만을 지원하고, 클라이언트로부터 입력되는 웹 요청 메시지에 대해 무조건 '404 File Not Found'로 응답하고, 상기 웹 요청 메시지를 출력하는 가상웹서버;상기 웹 요청 메시지에 대한 요청 주소별 접근 빈도 추이를 분석하여 침입 여부를 판단하여, 만약 침입으로 판단되는 경우 상기 웹 요청 메시지에 대한 경보를 생성하는 침입 판정기; 및상기 침입판정기에 의해 생성된 상기 경보에 대한 이메일 또는 시스템 로그를 생성하는 경보 생성기를 포함하는 것을 특징으로 하는 가상 웹서버 기반의 침입 유도 시스템.
- 삭제
- 제 1항에 있어서, 상기 침입판정기는,소정 기준 시간동안 발생한 상기 웹 요청 메시지의 상기 요청 주소별 접근 빈도에 대한, 단위 시간 동안 발생한 상기 웹 요청 메시지의 상기 요청 주소별 접 근 빈도의 비율을 계산하여, 만약 소정 검사 기준 임계값 이상이 되는 경우 침입으로 판단하는 것을 특징으로 하는 가상 웹서버 기반의 침입 유도 시스템.
- 제 3항에 있어서,상기 기준시간, 상기 단위시간, 및 상기 소정 검사 기준 임계값을 저장하는 환경설정DB를 더 포함하는 것을 특징으로 하는 가상 웹서버 기반의 침입 유도 시스템.
- 제 1항에 있어서,상기 침입판정기에 의해 생성되는 상기 경보는, 경보 ID, 공격시간, 공격자 IP, 공격자 포트, 공격 대상 IP, 공격 대상 포트, 연결 프로토콜, 연결 횟수, 및 요청 URL 중 어느 하나 이상을 포함하는 것을 특징으로 하는 가상 웹서버 기반의 침입 유도 시스템.
- 삭제
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| KR1020040074724A KR101074597B1 (ko) | 2004-09-17 | 2004-09-17 | 가상 웹서버 기반의 침입 유도 시스템 및 그 방법 |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| KR1020040074724A KR101074597B1 (ko) | 2004-09-17 | 2004-09-17 | 가상 웹서버 기반의 침입 유도 시스템 및 그 방법 |
Publications (2)
| Publication Number | Publication Date |
|---|---|
| KR20060025871A KR20060025871A (ko) | 2006-03-22 |
| KR101074597B1 true KR101074597B1 (ko) | 2011-10-17 |
Family
ID=37131243
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| KR1020040074724A Expired - Fee Related KR101074597B1 (ko) | 2004-09-17 | 2004-09-17 | 가상 웹서버 기반의 침입 유도 시스템 및 그 방법 |
Country Status (1)
| Country | Link |
|---|---|
| KR (1) | KR101074597B1 (ko) |
Families Citing this family (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN104486298B (zh) * | 2014-11-27 | 2018-03-09 | 小米科技有限责任公司 | 识别用户行为的方法及装置 |
| CN117278322B (zh) * | 2023-11-13 | 2024-02-20 | 国家工业信息安全发展研究中心 | Web入侵检测方法、装置、终端设备及存储介质 |
Citations (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20020069369A1 (en) | 2000-07-05 | 2002-06-06 | Tremain Geoffrey Donald | Method and apparatus for providing computer services |
| US20020083341A1 (en) * | 2000-12-27 | 2002-06-27 | Yehuda Feuerstein | Security component for a computing device |
-
2004
- 2004-09-17 KR KR1020040074724A patent/KR101074597B1/ko not_active Expired - Fee Related
Patent Citations (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20020069369A1 (en) | 2000-07-05 | 2002-06-06 | Tremain Geoffrey Donald | Method and apparatus for providing computer services |
| US20020083341A1 (en) * | 2000-12-27 | 2002-06-27 | Yehuda Feuerstein | Security component for a computing device |
Also Published As
| Publication number | Publication date |
|---|---|
| KR20060025871A (ko) | 2006-03-22 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| CN109951500B (zh) | 网络攻击检测方法及装置 | |
| CN1771709B (zh) | 用于产生网络攻击特征标记的方法和装置 | |
| US10225282B2 (en) | System, method and program product to identify a distributed denial of service attack | |
| CN1898923B (zh) | 拒绝服务攻击检测系统及拒绝服务攻击检测方法 | |
| US8561167B2 (en) | Web reputation scoring | |
| US7949716B2 (en) | Correlation and analysis of entity attributes | |
| US8762537B2 (en) | Multi-dimensional reputation scoring | |
| US8844034B2 (en) | Method and apparatus for detecting and defending against CC attack | |
| EP2865165B1 (en) | Method and device for secure content retrieval | |
| US8019689B1 (en) | Deriving reputation scores for web sites that accept personally identifiable information | |
| CN103957201B (zh) | 基于dns的域名信息处理方法、装置及系统 | |
| US8776224B2 (en) | Method and apparatus for identifying phishing websites in network traffic using generated regular expressions | |
| CN106453669B (zh) | 一种负载均衡方法及一种服务器 | |
| US20080175226A1 (en) | Reputation Based Connection Throttling | |
| JP2008520010A (ja) | Eメールアンチフィッシングインスペクタ | |
| CN111010409A (zh) | 加密攻击网络流量检测方法 | |
| CN110636068B (zh) | 在cc攻击防护中识别未知cdn节点的方法以及装置 | |
| US20080165682A1 (en) | Communication control apparatus, communication control method and communication control program product | |
| US8996640B2 (en) | System, method and computer readable medium for processing unsolicited electronic mail | |
| RU2679219C1 (ru) | СПОСОБ ЗАЩИТЫ СЕРВЕРА УСЛУГ ОТ DDoS АТАК | |
| CN108234486A (zh) | 一种网络监测方法及监测服务器 | |
| CN108234516B (zh) | 一种网络泛洪攻击的检测方法及装置 | |
| KR101074597B1 (ko) | 가상 웹서버 기반의 침입 유도 시스템 및 그 방법 | |
| CN112055028A (zh) | 网络攻击防御方法、装置、电子设备及存储介质 | |
| CN104104589B (zh) | 一种电子邮件发送方法和系统 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| PA0109 | Patent application |
St.27 status event code: A-0-1-A10-A12-nap-PA0109 |
|
| PG1501 | Laying open of application |
St.27 status event code: A-1-1-Q10-Q12-nap-PG1501 |
|
| R17-X000 | Change to representative recorded |
St.27 status event code: A-3-3-R10-R17-oth-X000 |
|
| R18-X000 | Changes to party contact information recorded |
St.27 status event code: A-3-3-R10-R18-oth-X000 |
|
| A201 | Request for examination | ||
| PA0201 | Request for examination |
St.27 status event code: A-1-2-D10-D11-exm-PA0201 |
|
| PN2301 | Change of applicant |
St.27 status event code: A-3-3-R10-R11-asn-PN2301 St.27 status event code: A-3-3-R10-R13-asn-PN2301 |
|
| D13-X000 | Search requested |
St.27 status event code: A-1-2-D10-D13-srh-X000 |
|
| D14-X000 | Search report completed |
St.27 status event code: A-1-2-D10-D14-srh-X000 |
|
| E902 | Notification of reason for refusal | ||
| PE0902 | Notice of grounds for rejection |
St.27 status event code: A-1-2-D10-D21-exm-PE0902 |
|
| E13-X000 | Pre-grant limitation requested |
St.27 status event code: A-2-3-E10-E13-lim-X000 |
|
| P11-X000 | Amendment of application requested |
St.27 status event code: A-2-2-P10-P11-nap-X000 |
|
| P13-X000 | Application amended |
St.27 status event code: A-2-2-P10-P13-nap-X000 |
|
| E701 | Decision to grant or registration of patent right | ||
| PE0701 | Decision of registration |
St.27 status event code: A-1-2-D10-D22-exm-PE0701 |
|
| GRNT | Written decision to grant | ||
| PR0701 | Registration of establishment |
St.27 status event code: A-2-4-F10-F11-exm-PR0701 |
|
| PR1002 | Payment of registration fee |
Fee payment year number: 1 St.27 status event code: A-2-2-U10-U11-oth-PR1002 |
|
| PG1601 | Publication of registration |
St.27 status event code: A-4-4-Q10-Q13-nap-PG1601 |
|
| R18-X000 | Changes to party contact information recorded |
St.27 status event code: A-5-5-R10-R18-oth-X000 |
|
| R18-X000 | Changes to party contact information recorded |
St.27 status event code: A-5-5-R10-R18-oth-X000 |
|
| R18-X000 | Changes to party contact information recorded |
St.27 status event code: A-5-5-R10-R18-oth-X000 |
|
| R18-X000 | Changes to party contact information recorded |
St.27 status event code: A-5-5-R10-R18-oth-X000 |
|
| R18-X000 | Changes to party contact information recorded |
St.27 status event code: A-5-5-R10-R18-oth-X000 |
|
| LAPS | Lapse due to unpaid annual fee | ||
| PC1903 | Unpaid annual fee |
Not in force date: 20141012 Payment event data comment text: Termination Category : DEFAULT_OF_REGISTRATION_FEE St.27 status event code: A-4-4-U10-U13-oth-PC1903 |
|
| PC1903 | Unpaid annual fee |
Ip right cessation event data comment text: Termination Category : DEFAULT_OF_REGISTRATION_FEE Not in force date: 20141012 St.27 status event code: N-4-6-H10-H13-oth-PC1903 |
|
| P22-X000 | Classification modified |
St.27 status event code: A-4-4-P10-P22-nap-X000 |
|
| R18-X000 | Changes to party contact information recorded |
St.27 status event code: A-5-5-R10-R18-oth-X000 |
|
| R18-X000 | Changes to party contact information recorded |
St.27 status event code: A-5-5-R10-R18-oth-X000 |