×

Log-based traceback system and method using centroid decomposition technique

  • US 8,307,441 B2
  • Filed: 11/21/2007
  • Issued: 11/06/2012
  • Est. Priority Date: 07/20/2007
  • Status: Expired due to Fees
First Claim
Patent Images

1. A log-based traceback system using centroid decomposition technique, the system comprising:

  • a log data input module collecting log data of an intrusion alarm from an intrusion detection system;

    a centroid node detection module generating a shortest path tree by applying a shortest path algorithm to network router connection information collected by a network administration server, detecting a centroid node by applying centroid decomposition technique removing a leaf-node to the shortest path tree, and generating a centroid tree whose node of each level is the detected centroid node; and

    a traceback processing module requesting log data of a router matched with the node of each level of the centroid tree, and tracing back a router identical to the log data of the collected intrusion alarm by comparing the log data of the router with the log data of the collected intrusion alarm as a router connected to a source of an attacker.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×