Method and apparatus for monitoring network

US10397248B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10397248-B2
Application numberUS-201615262803-A
CountryUS
Kind codeB2
Filing dateSep 12, 2016
Priority dateSep 15, 2015
Publication dateAug 27, 2019
Grant dateAug 27, 2019

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A disclosed network monitoring method includes: specifying a feature value for each of plural packet groups that were transferred between a first terminal and a second terminal on a connection between the first terminal and the second terminal; calculating a value representing variation in specified feature values; and determining whether the calculated value is equal to or greater than a predetermined threshold value.

First claim

Opening claim text (preview).

What is claimed is: 1. A network monitoring apparatus, comprising: a memory; and a processor configured to use the memory and execute a process, the process comprising: specifying, for each of a plurality of packet groups and from the plurality of packet groups, a feature value relating to a targeted attack, wherein each of the plurality of packet groups includes a plurality of packets that were communicated between an internal terminal and an external terminal on a connection between the internal terminal and the external terminal; calculating, for the plurality of packet groups, a value of a standard deviation of feature values specified for the plurality of packet groups; determining whether the calculated value is equal to or greater than a predetermined threshold value as an indication of the targeted attack; and outputting an alert regarding the targeted attack, after determining that the calculated value is equal to or greater than the predetermined threshold value, wherein the feature value includes at least one of a number of packets included in a packet group of the plurality of packet groups, a size of one or more packets included in the packet group, a time interval between the packet group and another packet group immediately before the packet group, and a value related to contents of data part of the plurality of packets included in the packet group, wherein the calculating is executed, when an IP address of a connection source of the connection is an IP address in an internal network, an IP address of a connection destination of the connection is an IP address in an external network, and a port number of the connection destination of the connection is a port number representing access to a web server. 2. The network monitoring apparatus as set forth in claim 1 , wherein the process further comprises determining whether a time period from a time when an initial packet of the connection was obtained is equal to or longer than a predetermined time, upon determining that the calculated value is equal to or greater than the predetermined threshold value, and the outputting is executed after determining that the time period is equal to or longer than the predetermined time. 3. The network monitoring apparatus as set forth in claim 1 , wherein the time interval between the group and the another group is a time interval between an initial packet of the group and an initial packet of the another group. 4. The network monitoring apparatus as set forth in claim 1 , wherein the process further comprises extracting plural packets to be included in each of the plurality of groups based on a time when each packet transferred on the connection was obtained. 5. A non-transitory computer-readable storage medium storing a program for causing a computer to execute a process, the process comprising: specifying, for each of a plurality of packet groups and from the plurality of packet groups, a feature value relating to a targeted attack, wherein each of the plurality of packet groups includes a plurality of packets that were communicated between an internal terminal and an external terminal on a connection between the internal terminal and the external terminal; calculating, for the plurality of packet groups, a value of a standard deviation of feature values specified for the plurality of packet groups; determining whether the calculated value is equal to or greater than a predetermined threshold value as an indication of the targeted attack; and outputting an alert regarding the targeted attack, after determining that the calculated value is equal to or greater than the predetermined threshold value, wherein the feature value includes at least one of a number of packets included in a packet group of the plurality of packet groups, a size of one or more packets included in the packet group, a time interval between the packet group and another packet group immediately before the packet group, and a value related to contents of data part of the plurality of packets included in the packet group, wherein the calculating is executed, when an IP address of a connection source of the connection is an IP address in an internal network, an IP address of a connection destination of the connection is an IP address in an external network, and a port number of the connection destination of the connection is a port number representing access to a web server. 6. The non-transitory computer-readable storage medium as set forth in claim 5 , wherein the process further comprises determining whether a time period from a time when an initial packet of the connection was obtained is equal to or longer than a predetermined time, upon determining that the calculated value is equal to or greater than the predetermined threshold value, and the outputting is executed after determining that the time period is equal to or longer than the predetermined time. 7. The non-transitory computer-readable storage medium as set forth in claim 5 , wherein the time interval between the group and the another group is a time interval between an initial packet of the group and an initial packet of the another group. 8. The non-transitory computer-readable storage medium as set forth in claim 5 , wherein the process further comprises extracting plural packets to be included in each of the plurality of groups based on a time when each packet transferred on the connection was obtained. 9. A network monitoring method, comprising: specifying, by using a computer, for each of a plurality of packet groups and from the plurality of packet groups, a feature value relating to a targeted attack, wherein each of the plurality of packet groups includes a plurality of packets that were communicated between an internal terminal and an external terminal on a connection between the internal terminal and the external terminal; calculating, by using the computer, for the plurality of packet groups, a value of a standard deviation of feature values specified for the plurality of packet groups; determining, by using the computer, whether the calculated value is equal to or greater than a predetermined threshold value as an indication of the targeted attack; and outputting, by using the computer, an alert regarding the targeted attack, after determining that the calculated value is equal to or greater than the predetermined threshold value, wherein the feature value includes at least one of a number of packets included in a packet group of the plurality of packet groups, a size of one or more packets included in the packet group, a time interval between the packet group and another packet group immediately before the packet group, and a value related to contents of data part of the plurality of packets included in the packet group, wherein the calculating is executed, when an IP address of a connection source of the connection is an IP address in an internal network, an IP address of a connection destination of the connection is an IP address in an external network, and a port number of the connection destination of the connection is a port number representing access to a web server. 10. The network monitoring method as set forth in claim 9 , wherein the process further comprises determining, by using the computer, whether a time period from a time when an initial packet of the connection was obtained is equal to or longer than a predetermined time, upon determining that the calculated value is equal to or greater than the predetermined threshold value, and the outputting is executed after determining that the time period is equal to or longer than the predetermined time. 11. The network monitoring method as set forth in claim 9 , wherein the time int

Assignees

Inventors

Classifications

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10397248B2 cover?
A disclosed network monitoring method includes: specifying a feature value for each of plural packet groups that were transferred between a first terminal and a second terminal on a connection between the first terminal and the second terminal; calculating a value representing variation in specified feature values; and determining whether the calculated value is equal to or greater than a prede…
Who is the assignee on this patent?
Fujitsu Ltd
What technology area does this patent fall under?
Primary CPC classification H04L63/1416. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Aug 27 2019 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 5 related publications on this page (citations in our corpus or others sharing the same primary CPC).