ABNORMAL TRAFFIC DETECTION APPARATUS, ABNORMAL TRAFFIC DETECTION METHOD AND ABNORMAL TRAFFIC DETECTION PROGRAM
First Claim
1. An abnormal traffic detection apparatus that, when traffics are transmitted and received between communication apparatuses connected to the Internet via a switch, monitors traffics passing through the switch and uses traffic information on the monitored traffics to detect abnormal traffics toward the communication apparatus, comprising:
- an amount information storing unit configured to store amount information on an amount of traffics as an amount information table, the amount information table corresponding to each communication apparatus that is a destination of the traffics, the amount information being included in the traffic information;
a storage controlling unit configured to identify a router, which connects the communication apparatus as the destination of the traffics and the switch, and a destination IP address of the traffics on the basis of the traffic information, the storage controlling unit configured to register, when the identified destination IP address is a new destination IP address not stored in the amount information table, the new destination IP address in the amount information table and then store the amount information in the amount information table, which corresponds to the identified communication apparatus, the storage controlling unit configured to store, when the identified destination IP address is a destination IP address already stored in the amount information table, the amount information in the amount information table, which corresponds to the identified communication apparatus; and
an abnormal traffic judging unit that judges, for each of the communication apparatuses or each of the routers, whether the traffic amount flowing through the switch is abnormal on the basis of the amount information stored in the amount information table.
1 Assignment
0 Petitions
Accused Products
Abstract
An abnormal traffic detection apparatus for detecting an abnormal traffic toward a communication apparatus by using information on traffics passing through a switch, comprising destination IP address counting units (C1 to C4) configured to store amount information on amount of traffics as an amount information table corresponding to each communication apparatus, a traffic separating unit (21) for registering amount information on a new destination IP address in the amount information table corresponding to the destination IP address, each time a traffics having the new destination IP address passes through the switch, and storing the amount information in the amount information table corresponding to each communication apparatus, and abnormal traffic judging units (J1 to J4) for detecting an abnormality of the traffic amount flowing through the switch on the basis of the amount information stored in the amount information table.
44 Citations
9 Claims
-
1. An abnormal traffic detection apparatus that, when traffics are transmitted and received between communication apparatuses connected to the Internet via a switch, monitors traffics passing through the switch and uses traffic information on the monitored traffics to detect abnormal traffics toward the communication apparatus, comprising:
-
an amount information storing unit configured to store amount information on an amount of traffics as an amount information table, the amount information table corresponding to each communication apparatus that is a destination of the traffics, the amount information being included in the traffic information; a storage controlling unit configured to identify a router, which connects the communication apparatus as the destination of the traffics and the switch, and a destination IP address of the traffics on the basis of the traffic information, the storage controlling unit configured to register, when the identified destination IP address is a new destination IP address not stored in the amount information table, the new destination IP address in the amount information table and then store the amount information in the amount information table, which corresponds to the identified communication apparatus, the storage controlling unit configured to store, when the identified destination IP address is a destination IP address already stored in the amount information table, the amount information in the amount information table, which corresponds to the identified communication apparatus; and an abnormal traffic judging unit that judges, for each of the communication apparatuses or each of the routers, whether the traffic amount flowing through the switch is abnormal on the basis of the amount information stored in the amount information table. - View Dependent Claims (2, 3)
-
-
4. An abnormal traffic detection method that, when traffics are transmitted and received between communication apparatuses connected to the Internet via a switch, monitors traffics passing through the switch and uses traffic information on the monitored traffics to detect abnormal traffics toward the communication apparatuses, comprising:
-
a traffic information acquiring step of acquiring the traffic information; a destination identifying step of identifying a router, which connects the communication apparatus as a destination of the traffics and the switch, and a destination IP address of the traffics on the basis of the traffic information; an amount information storing step of storing amount information on an amount of traffics included in the traffic information as an amount information table corresponding to each communication apparatus that is a destination of the traffics, in which when the identified destination IP address is a new destination IP address not stored in the amount information table, the new destination IP address is registered in the amount information table and then the amount information is stored in the amount information table, which corresponds to the identified communication apparatus, and when the identified destination IP address is a destination IP address already stored in the amount information table, the amount information is stored in the amount information table, which corresponds to the identified communication apparatus; and an abnormal traffic judging step of judging, for each of the communication apparatuses or each of the routers, whether the traffic amount flowing through the switch is abnormal on the basis of the amount information stored in the amount information table. - View Dependent Claims (5, 6)
-
-
7. An abnormal traffic detection program that uses traffic information on traffics, which are monitored when transmitted and received passing through a switch between communication apparatuses connected to the Internet via the switch, to cause a computer to detect abnormal traffics toward the communication apparatuses, comprising:
-
a traffic information acquiring step of acquiring the traffic information; a destination identifying step of identifying a router, which connects the communication apparatus as a destination of the traffics and the switch, and a destination IP address of the traffics on the basis of the traffic information; an amount information storing step of storing amount information on an amount of traffics included in the traffic information as an amount information table corresponding to each communication apparatus that is a destination of the traffics, in which when the identified destination IP address is a new destination IP address not stored in the amount information table, the new destination IP address is registered in the amount information table and then the amount information is stored in the amount information table, which corresponds to the identified communication apparatus, and when the identified destination IP address is a destination IP address already stored in the amount information table, the amount information is stored in the amount information table, which corresponds to the identified communication apparatus; and an abnormal traffic judging step of judging, for each of the communication apparatuses or each routers, whether the traffic amount flowing through the switch is abnormal on the basis of the amount information stored in the amount information table. - View Dependent Claims (8, 9)
-
Specification