×

Attack defending system and attack defending method

  • US 7,958,549 B2
  • Filed: 07/25/2007
  • Issued: 06/07/2011
  • Est. Priority Date: 08/20/2002
  • Status: Active Grant
First Claim
Patent Images

1. An attack defending system provided at an interface between an internal network and an external network, comprising a decoy device and a firewall device, wherein the firewall device inputs an input IP packet from the external network and forwards it to one of the decoy device and the internal network, whereinthe firewall device comprises:

  • a microprocessor programmed to execute;

    a destination selector for selecting one of the internal network and the decoy device as a destination of the input IP packet based on header information of the input IP packet and a distribution condition; and

    a confidence manager for managing confidence levels for source IP addresses of a plurality of input IP packets,wherein the destination selector obtains a confidence level for a source IP address of the input IP packet from the confidence manager and selects a destination of the input IP packet depending on whether the confidence level satisfies the distribution condition,the confidence level is calculated based on the header information of the input IP packet and an input history of previous input IP packets.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×