FIELD: computer engineering.
SUBSTANCE: method includes the following steps: transfer of the intercepted network packets to the packet grouping tool and issuance of network packets divided into groups for transferring them to the classification tool, issuing delimited fields of network packet headers for transferring them to the clustering tool, issuing types of delimited fields for transmission them to a device for determining the roles of computer network nodes, issuing node roles, recording the address data of computer network nodes in the interface cattalo, recording signals, including roles, node address data and semantic fields of network packet headers, in the signal dictionary, forming a validation sample and for transmission to simulating agents, issuing responses to validation set signals; assignment of responses to signals that do not belong to the validation sample to normal reactions of computer network nodes to network packets, if the reactions of agents to the signals of the validation sample coincide with the expected reactions.
EFFECT: revealing normal reactions of computer network nodes to network packets related to unknown traffic.
12 cl, 6 dwg
Title | Year | Author | Number |
---|---|---|---|
METHOD FOR DETECTING ANOMALIES IN OPERATION OF AUTOMATED SYSTEM NETWORK | 2020 |
|
RU2738460C1 |
METHOD FOR DETECTION OF ANOMALIES IN OPERATION OF HIGHLY LOADED NETWORK OF AUTOMATED TELECOMMUNICATION SYSTEM | 2021 |
|
RU2787078C1 |
METHOD OF PROCESSING NETWORK TRAFFIC DATAGRAMS FOR PROTECTING INFORMATION COMPUTER SYSTEMS (VERSIONS) | 2012 |
|
RU2472217C1 |
METHOD OF ROUTING TRAFFIC, HAVING PRIORITY CLASS IN COMMUNICATION NETWORK, INCLUDING TWO AND MORE OPERATORS | 2016 |
|
RU2631144C1 |
METHOD OF PROCESSING NETWORK TRAFFIC DATAGRAMS FOR HIDING CORRESPONDING PAIRS OF SUBSCRIBERS OF INFORMATION-TELECOMMUNICATION SYSTEMS | 2014 |
|
RU2586840C1 |
METHOD FOR MONITORING NETWORK ACTIVITY OF COMPUTER NETWORK NODES | 2023 |
|
RU2809918C1 |
METHOD FOR DETECTING ANOMALOUS NETWORK TRAFFIC | 2023 |
|
RU2811840C1 |
PRIVATE NICKNAMES OF END POINTS FOR ISOLATED VIRTUAL NETWORKS | 2015 |
|
RU2669525C1 |
METHOD FOR TRACKING SESSIONS IN NETWORK TRAFFIC | 2022 |
|
RU2786178C1 |
METHOD FOR FILTERING NETWORK TRAFFIC BASED ON RULES WITH A MASK DURING PACKET SWITCHING | 2022 |
|
RU2795295C1 |
Authors
Dates
2023-08-22—Published
2022-10-25—Filed