Method and apparatus for improving network security

US9762594B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9762594-B2
Application numberUS-201414583367-A
CountryUS
Kind codeB2
Filing dateDec 26, 2014
Priority dateDec 27, 2013
Publication dateSep 12, 2017
Grant dateSep 12, 2017

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A method and an apparatus for improving network security are provided. The method includes obtaining, by a control node, alarm information, where the alarm information includes address information of an attack source that attacks a subnet of at least two subnets and identification information of the attacked subnet of the at least two subnets, using, by the control node, the alarm information to sort the attack sources in descending order of threat levels, and using a sorting result as a blacklist, and sending, by the control node, the obtained blacklist to at least one subnet that is not attacked yet in the network system. The method and apparatus are applicable to collaborative defense among multiple subnets.

First claim

Opening claim text (preview).

What is claimed is: 1. A method for improving network security, wherein a network comprises a control node and at least two subnets in communication connection with the control node, and wherein the method comprises: obtaining, by the control node, alarm information, wherein the alarm information comprises address information of attack sources that attack a subnet of the at least two subnets and identification information of the attacked subnet of the at least two subnets; sorting, by the control node, the attack sources in descending order of threat levels according to the alarm information; obtaining a blacklist based on a sorting result, wherein the blacklist includes the attack sources and threat level corresponding to each attack source of the attack sources; and sending, by the control node, the obtained blacklist to at least one subnet that is not attacked yet in the network, wherein before sorting the attack sources in descending order of threat levels according to the alarm information, the method further comprises: determining harm information of each subnet, wherein the harm information comprises the number of attack sources that attack a subnet, the number of attacked ports of this subnet, duration of attack on this subnet, and a sum of amounts of data received by this subnet from all attack sources; and obtaining a vulnerability value according to the harm information of each subnet, wherein sorting the attack sources in descending order of threat levels according to the alarm information comprises: determining, for an attacked subnet, a danger level imposed by each attack source that attacks the subnet on the subnet using the threat value of each attack source that attacks the subnet, a value of association between each attack source that attacks the subnet and the subnet and the vulnerability value of the subnet to; and sorting the attack sources ng order of the danger levels. 2. The method for improving network security according to claim 1 , wherein before sorting the attack sources in descending order of threat levels according to the alarm information, the method further comprises: determining threat information of each attack source, wherein the threat information comprises duration of an attack launched by the attack source, an amount of data from the attack source, the number of subnets attacked by the attack source, and the number of ports attacked by the attack source; and obtaining a threat value of each attack source according to the threat information of the attack source, wherein sorting the attack sources in descending order of threat levels according to the alarm information comprises sorting the attack sources in descending order of the threat values of the attack sources according to the alarm information. 3. The method for improving network security according to claim 1 , wherein before sorting the attack sources in descending order of threat levels according to the alarm information, the method further comprises: determining a value of association between each attack source and all the attacked subnets according to r s =[(1−aW) −1 −I]·b s , wherein r s represents a value of association between one attack source and all the attacked subnets, b s represents a Boolean vector of an attack relationship between this attack source and all the attacked subnets, s represents an identifier of this attack source, a represents a threat value of this attack source, I represents an identity matrix, and W represents an address of this attack source, wherein sorting the attack sources in descending order of threat levels according to the alarm information comprises: determining, for an attacked subnet, a danger level imposed by each attack source that attacks the subnet on the subnet using a threat value of each attack source that attacks the subnet and a value of association between each attack source that attacks the subnet; and sorting the attack sources that attack the subnet in descending order of danger levels imposed by the attack sources. 4. The method for improving network security according to claim 1 , wherein obtaining, by the control node, alarm information comprises obtaining, by the control node, the alarm information from an Openflow asynchronization message sent by the subnet. 5. A control node for improving network security, wherein a network comprises the control node and at least two subnets in communication connection with the control node, and wherein the control node comprises: a processor; and a storage medium, wherein instructions are stored on the storage medium and are executable by the processor to instruct the processor to: obtain alarm information, wherein the alarm information comprises address information of attack sources that attack a subnet of the at least two subnets and identification information of the attacked subnet of the at least two subnets; sort the attack sources in descending order of threat levels according to the alarm information; obtain a blacklist based on a sorting result, wherein the blacklist includes the attack sources and threat level corresponding to each attack source of the attack sources; and send the obtained blacklist to at least one subnet that is not attacked yet in the network, wherein before the instructions to sort the attack sources, the instructions further comprise instructions to instruct the processor to: determine harm information of each subnet, wherein the harm information comprises the number of attack sources that attack a subnet, the number of attacked parts of this subnet duration f attack on this subnet, and a sum of amounts of data received by this subnet from all attack sources; and obtain a vulnerability value according to the harm information of each subnet, wherein the instructions to use the alarm information to sort the attack sources in descending order of the threat values of the attack sources comprises instructions that instruct the processor to: determine, for an attacked subnet, a danger level imposed by each attack source that attacks the subnet on the subnet by using the threat value of each attack source that attacks the subnet, a value of association between each attack source that attacks the subnet and the subnet, and the vulnerability value of the subnet; and sort the attack sources that attack the subnet in descending order of the danger levels. 6. The control node for improving network security according to claim 5 , wherein the instructions to sort the attack sources in descending order of threat levels according to the alarm information comprise instructions to instruct the processor to: determine the number of subnets attacked by each attack source of multiple attack sources corresponding to the address information of the attack sources by using the identification information of the attacked subset; and sort the attack sources in descending order of the number of the attacked subnets. 7. The control node for improving network security according to claim 5 , wherein the instructions to use the alarm information to sort the attack sources in descending order of threat levels comprise instructions to instruct the processor to: determine the number of ports attacked by each attack source of multiple attack sources corresponding to the address information of the attack sources by using the identification information of the attacked subnet; and sort the attack sources in descending order of the number of the ports attacked by each attack source. 8. The control node for improving network security according to claim 5 , wherein before the instructions to sort the attack sources in descending order of threat levels according to the alarm information, the instructions further comprise instructions to i

Assignees

Inventors

Classifications

  • involving event detection and direct action · CPC title

  • H04L63/101Primary

    Access control lists [ACL] · CPC title

  • Event detection, e.g. attack signature detection · CPC title

  • Tracing the source of attacks · CPC title

  • Detecting local intrusion or implementing counter-measures · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9762594B2 cover?
A method and an apparatus for improving network security are provided. The method includes obtaining, by a control node, alarm information, where the alarm information includes address information of an attack source that attacks a subnet of at least two subnets and identification information of the attacked subnet of the at least two subnets, using, by the control node, the alarm information t…
Who is the assignee on this patent?
Huawei Tech Co Ltd
What technology area does this patent fall under?
Primary CPC classification H04L63/101. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Sep 12 2017 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).