×

Network-based attack tracing system and method using distributed agent and manager system

  • US 20030159069A1
  • Filed: 10/18/2002
  • Published: 08/21/2003
  • Est. Priority Date: 02/19/2002
  • Status: Abandoned Application
First Claim
Patent Images

1. A network-based attack tracing system using a distributed attack detection agent and manager system, the system comprising:

  • an agent for detecting an external attack, storing a result of detection in an alarm log DB, and performing a log analysis through a real-time monitoring of the alarm log DB, the agent changing analyzed log information to attack information, storing the attack information in an attack log DB, and then transmitting the attack information through a UDP communication;

    a request manager for performing a search request of IP information included in the attack information received from the agent; and

    a reply manager for searching an attack IP from the alarm log DB of an agent of a sub network to which the corresponding attack IP of its own network in accordance with the IP search request from the request manager, and transmitting a result of search to the request manager;

    wherein if there is another passing IP, the request manager continuously requests the attack information search to a reply manager of another network, and if the above process is completed, the request manager stores a result of tracing a hacking path in a tracing result DB.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×