METHOD OF DETECTING LOCAL AREA NETWORK DEVICES, OPERATING IN NETWORK TRAFFIC CAPTURE MODE Russian patent published in 2009 - IPC H04L12/403 G06F17/18 

Abstract RU 2367101 C2

FIELD: physics; computer engineering.

SUBSTANCE: invention relates to computer engineering and can be used in automated information security media with the objective of monitoring local area networks to detect computer attacks on network resources. The method of detecting local area network devices, operating in network traffic capture mode, involves using a control network node for detecting devices, in which a threshold value for the coefficient of correlation is given. The response time of workstations on the network is then determined. ICMP packets with a submit field, which is not in the probed network, are broadcast on the network, and network loading is recorded. After that, the correlation coefficient of values of network loading parametres and response time of workstations is determined and, if the correlation coefficient exceeds the threshold value, there is a device on the network, operating in network traffic capture mode.

EFFECT: reduced number of false alarms on results of analysing response time of network nodes and increased probability of detecting workstations, operating in network traffic capture mode.

3 dwg

Similar patents RU2367101C2

Title Year Author Number
METHOD FOR DETECTING ANOMALOUS WORK OF NETWORK SERVER (OPTIONS) 2016
  • Eliseev Vladimir Leonidovich
  • Shabalin Yurij Dmitrievich
RU2630415C2
METHOD OF CREATING A SECURE L2-CONNECTION BETWEEN PACKET SWITCHED NETWORKS 2018
  • Guzev Oleg Yurevich
  • Chizhov Ivan Vladimirovich
RU2694585C1
NETWORK SYSTEM AND COMMUNICATION TRAFFIC CONTROL METHOD 2011
  • Sato Sikhomi
RU2576480C2
METHOD AND APPARATUS FOR HYBRID SWITCHING OF DISTRIBUTED MULTILEVEL TELECOMMUNICATION SYSTEM, SWITCHING UNIT AND TEST TRAFFIC GENERATOR 2014
  • Budko Nikita Pavlovich
  • Budko Pavel Aleksandrovich
  • Vinogradenko Aleksej Mikhajlovich
  • Litvinov Aleksandr Igorevich
RU2542906C1
COMMUNICATION DEVICE FOR CONNECTING A CLIENT TO GROUP CALL IN GROUP COMMUNICATION NETWORK 2003
  • Krokett Duglas M.
  • Rouzen Ehrik K.
  • Madzhenti Mark
RU2316150C2
METHOD FOR GROUP TRANSMISSION OF PACKETS VIA SOFTWARE-CONFIGURABLE NETWORKS 2015
RU2611990C1
METHOD OF DETECTING UNAUTHORIZED USE OF NETWORK DEVICES OF LIMITED FUNCTIONALITY FROM A LOCAL NETWORK AND PREVENTING DISTRIBUTED NETWORK ATTACKS FROM THEM 2018
  • Gurina Anastasiya Olegovna
  • Eliseev Vladimir Leonidovich
RU2703329C1
SYSTEM FOR AGGREGATION OF NETWORK DATA IN COMPUTER NETWORKS 2019
  • Marchenkov Aleksej Aleksandrovich
  • Esin Anton Anatolevich
RU2694025C1
COMPUTING APPARATUS AND METHOD FOR IDENTIFYING COMPROMISED APPARATUSES BASED ON DNS TUNNELLING DETECTION 2021
  • Afonin Anton Viktorovich
RU2777348C1
TROUBLESHOOTING Wi-Fi CONNECTIVITY BY MEASURING ROUND TRIP TIME OF PACKETS SENT WITH DIFFERENT MODULATION RATES 2012
  • Van Dorselar Karel
  • Van Ost Kun
  • Djume Silven
  • Van De Pul Dirk
RU2577336C2

RU 2 367 101 C2

Authors

Bochkov Maksim Vadimovich

Kozachok Andrej Vasil'Evich

Dates

2009-09-10Published

2007-05-07Filed