2020.11.23

ABNORMAL PACKET DETECTION APPARATUS AND METHOD

United States

Overview

An abnormal packet detection apparatus and method are provided. The abnormal packet detection apparatus stores a whitelist corresponding to a protocol port, wherein the whitelist includes at least one legal packet record. Each legal packet record includes a legal packet length, a legal source address, and a legal variation position set and corresponds to a reference packet. The abnormal packet detection apparatus determines that a current packet length and a current source address of a to-be-analyzed packet are respectively the same as the legal packet length and the legal source address of a reference packet record among the at least one legal packet record, determines a current variation position of the to-be-analyzed packet by comparing the to-be-analyzed packet with the reference packet corresponding to the reference packet record, and generates a detection result by comparing the current variation position with the legal variation position set of the reference packet record.

Category

資訊安全
內容安全及威脅管理
Appl. Type

發明

Status

Patented

Appl. No.

17/102,209

Patent No

US11,425,094B2

Filing Date

2020.11.23

Expired Date

2041.04.17

Notification

2023.11.10