×

Abnormal traffic detection apparatus, abnormal traffic detection method and abnormal traffic detection program

  • US 8,422,386 B2
  • Filed: 09/25/2008
  • Issued: 04/16/2013
  • Est. Priority Date: 10/02/2007
  • Status: Active Grant
First Claim
Patent Images

1. An abnormal traffic detection apparatus that, when traffics are transmitted and received between a plurality of ISPs (Internet Service Providers) connected to the Internet via a switch, monitors traffics passing through the switch and uses traffic information on the monitored traffics to detect abnormal traffics toward the ISPs, comprising:

  • an amount information storing unit configured to store amount information on an amount of traffics as an amount information table, the amount information table corresponding to each ISP that is a destination of the traffics, the amount information being included in the traffic information;

    a storage controlling unit configured to identify the ISP which is a destination of the traffics on the basis of one or more destination IP addresses of the traffic information, the storage controlling unit configured to, when a destination IP address identified by the traffic information is already stored in the amount information table corresponding to the identified ISP, store the identified IP address and the amount information in the amount information table corresponding to the identified ISP, and the storage controlling unit configured to, when a destination IP address identified by the traffic information is not stored in the amount information table corresponding to the identified ISP, store the amount information in the amount information table corresponding to the identified ISP; and

    an abnormal traffic judging unit that judges, for each of the ISPs, whether the traffic amount flowing through the switch is abnormal on the basis of the amount information stored in the amount information table.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×