FIELD: physics.
SUBSTANCE: invention relates to information security. Technical result is achieved due to preliminary analysis of incoming traffic flow on ownership of traffic to a previously established connection by means of a control unit of incoming packets, parsing packets to obtain data from packets on a channel, network, transport and application levels through a deep packet filtering device (DPI), decomposing obtained data from packets into clusters by a clustering unit, making a decision on each packet in clusters based on established rules for processing network packets through a decision making unit, detecting deviations of network traffic, which complies with processing rules, from a normal traffic profile of packets through an anomaly detection unit, updating established rules for processing network packets by means of a log file unit.
EFFECT: technical result consists in faster processing of network traffic based on clustering data with simultaneous thorough filtering thereof due to that each packet undergoes checking a set of rules, as well as detecting anomalies.
1 cl, 1 dwg
Title | Year | Author | Number |
---|---|---|---|
FIREWALL SYSTEM | 2017 |
|
RU2691192C1 |
SYSTEM AND METHOD FOR ANALYSING INCOMING TRAFFIC FLOW | 2023 |
|
RU2812087C1 |
METHOD FOR DETECTING ANOMALIES IN OPERATION OF AUTOMATED SYSTEM NETWORK | 2020 |
|
RU2738460C1 |
METHOD OF NETWORK PROTOCOL DEEP REVIEW FOR ANALYSIS AND FILTRATION OF THEIR CONTENTS | 2016 |
|
RU2640295C1 |
SOFTWARE AND HARDWARE COMPLEX FOR ENSURING SECURED DATA EXCHANGE BETWEEN TECHNICAL EQUIPMENT OF TERMINAL AUTOMATED SYSTEMS | 2023 |
|
RU2809234C1 |
SOFTWARE-HARDWARE SYSTEM FOR DATA EXCHANGE OF AUTOMATED SYSTEMS | 2020 |
|
RU2727090C1 |
METHOD FOR DETECTING NORMAL REACTIONS OF COMPUTER NETWORK NODES TO NETWORK PACKETS RELATED TO UNKNOWN TRAFFIC | 2022 |
|
RU2802164C1 |
METHOD FOR FILTERING NETWORK TRAFFIC BASED ON RULES WITH A MASK DURING PACKET SWITCHING | 2022 |
|
RU2795295C1 |
PROTECTION OF WEB APPLICATIONS WITH INTELLIGENT NETWORK SCREEN WITH AUTOMATIC APPLICATION MODELING | 2017 |
|
RU2659482C1 |
PROTECTIVE SYSTEM FOR VIRTUAL CHANNEL OF CORPORATE NETWORK USING AUTHENTICATION ROUTER AND BUILT AROUND SHARED COMMUNICATION NETWORK CHANNELS AND SWITCHING FACILITIES | 1999 |
|
RU2163745C2 |
Authors
Dates
2019-08-16—Published
2017-12-27—Filed