Apparatus and method for protecting communication pattern of network traffic

US9356958B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9356958-B2
Application numberUS-201414444794-A
CountryUS
Kind codeB2
Filing dateJul 28, 2014
Priority dateSep 25, 2013
Publication dateMay 31, 2016
Grant dateMay 31, 2016

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

An apparatus for protecting traffic trend in a network of a control system using artificial communication is provided. In accordance with an embodiment, the apparatus includes a communication terminal device installed in a network and configured to create and filter artificial communication. A communication server device determines whether to create artificial communication at a current time in the communication terminal device, requests a transmitting side-communication terminal device to create artificial communication, and requests a receiving side-communication terminal device to filter the artificial communication.

First claim

Opening claim text (preview).

What is claimed is: 1. An apparatus, comprising: a server for protecting communication pattern between parties in a network, the sever comprising one or more units which being configured and executed by a hardware processor using algorithms which associated with least one non-transitory storage device, the algorithm which when executed, causes the processor to perform the one or more units, the one or more units comprising, a creation determination unit for determining whether to create artificial communication during performance of normal communication over a network, the determining to create the artificial communication is performed using the following algorithm, in response to detection of communication period of the network, the creation determination unit for calculating a probability of artificial communication based on the communication period, in response to detection of predetermined unit time being elapsed, the creation determination unit for determining to create artificial communication at current time based on the calculated probability of the artificial communication, wherein a random number value of the current time is resulting value obtained by performing a modulo operation on the current time, in response to detection of the creation of the artificial communication, a creation requesting unit for requesting a transmitting side-communication terminal device of the network to create artificial communication, and requesting receiving side-communication terminal device to filter artificial communication, wherein the creation determination unit calculates a normal distribution, having a value corresponding to half of the communication period of the network as a mean, as the artificial communication creation probability. 2. The communication server device of claim 1 , wherein the creation determination unit determines whether to create the artificial communication by additionally considering a preset creation determination time. 3. The communication server device of claim 2 , wherein the creation determination unit generates a random number value every creation determination time, compares a creation probability for a value based on a current time with the random number value, and then determines whether to create artificial communication at the current time. 4. The communication server device of claim 1 , wherein the creation requesting unit requests a receiving side-communication terminal device to filter the artificial communication received from the transmitting side-communication terminal device. 5. A communication terminal device in an apparatus for protecting a communication pattern of network traffic, comprising: one or more units being configured and executed by a hardware processor using algorithms which associated with least one non-transitory storage device, the algorithm which when executed, causes the processor to perform the one or more units, the one or more units comprising, a communication creation unit for, in response to receipt of an artificial communication creation request transmitted from a communication server device, creating artificial communication, the artificial communication creation request being generated during performance of normal communication over a network using the following algorithm; in response to detection of communication period of the network, the creation determination unit for calculating a probability of artificial communication based on the communication period, in response to detection of predetermined unit time being elapsed, the creation determination unit for determining to create artificial communication at current time based on the calculated probability of the artificial communication, wherein a random number value of the current time is resulting value obtained by performing a modulo operation on the current time, in response to detection of the creation of the artificial communication creation request; a transmission/reception unit for transmitting the created artificial communication to a receiving side-communication terminal device, and receiving artificial communication from a transmitting side-communication terminal device; and a filtering unit for, if an artificial communication filtering request is received from the communication server device, filtering the artificial communication received from the transmitting side-communication terminal device wherein the creation determination unit calculates a normal distribution, having a value corresponding to half of the communication period of the network as a mean, as the artificial communication creation probability. 6. The communication terminal device of claim 5 , further comprising: a response message generation unit for, if the artificial communication is received or filtered, generating a response message to results of reception or filtering based on a predefined response template. 7. A computer-implemented method using a processor for protecting a communication pattern of network traffic, comprising: determining, by the processor, whether to create artificial communication during performance of normal communication over a network according to the following steps, the steps comprising, in response to detection of communication period of the network, calculating a probability of artificial communication based on the communication period, in response to detection of predetermined unit time being elapsed, determining to create artificial communication at current time based on the calculated probability of the artificial communication, wherein a random number value of the current time is resulting value obtained by performing a modulo operation on the current time, in response to detection of the creation of the artificial communication, requesting a transmitting side-communication terminal device of the network to create artificial communication, and requesting receiving side-communication terminal device to filter artificial communication, wherein the creation determination unit calculates a normal distribution, having a value corresponding to half of the communication period of the network as a mean, as the artificial communication creation probability. 8. The method of claim 7 , wherein determining whether to create artificial communication comprises calculating a probability of artificial communication being created in consideration of a communication period of the network, and determining whether to create artificial communication, based on the calculated artificial communication creation probability. 9. The method of claim 8 , wherein determining whether to create artificial communication comprises determining whether to create the artificial communication by additionally considering a preset creation determination time. 10. The method of claim 9 , wherein determining whether to create artificial communication comprises: generating a random number value every creation determination time; and comparing a creation probability for a value based on a current time with the random number value. 11. The method of claim 7 , further comprising: requesting a receiving side-communication terminal device to filter the artificial communication created by the transmitting side-communication terminal device.

Assignees

Inventors

Classifications

  • Passive attacks, e.g. eavesdropping or listening without modification of the traffic monitored · CPC title

  • using deception as countermeasure, e.g. honeypots, honeynets, decoys or entrapment · CPC title

  • H04L9/00Primary

    {Cryptographic mechanisms or cryptographic} arrangements for secret or secure communications; Network security protocols · CPC title

  • Arrangements for preventing the taking of data from a data transmission channel without authorisation (means for verifying the identity or the authority of a user of a secure or secret communication system H04L9/32) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9356958B2 cover?
An apparatus for protecting traffic trend in a network of a control system using artificial communication is provided. In accordance with an embodiment, the apparatus includes a communication terminal device installed in a network and configured to create and filter artificial communication. A communication server device determines whether to create artificial communication at a current time in…
Who is the assignee on this patent?
Korea Electronics Telecomm
What technology area does this patent fall under?
Primary CPC classification H04L63/1491. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue May 31 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).