JP4574675B2 - 通信管理システム - Google Patents
通信管理システム Download PDFInfo
- Publication number
- JP4574675B2 JP4574675B2 JP2007513543A JP2007513543A JP4574675B2 JP 4574675 B2 JP4574675 B2 JP 4574675B2 JP 2007513543 A JP2007513543 A JP 2007513543A JP 2007513543 A JP2007513543 A JP 2007513543A JP 4574675 B2 JP4574675 B2 JP 4574675B2
- Authority
- JP
- Japan
- Prior art keywords
- data
- communication
- communication control
- database
- communication data
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Expired - Fee Related
Links
- 238000004891 communication Methods 0.000 title claims description 397
- 238000011144 upstream manufacturing Methods 0.000 claims description 5
- 230000008859 change Effects 0.000 claims description 4
- 238000012545 processing Methods 0.000 description 77
- 238000000034 method Methods 0.000 description 63
- 230000008569 process Effects 0.000 description 37
- 238000005516 engineering process Methods 0.000 description 32
- 238000007726 management method Methods 0.000 description 31
- 230000002159 abnormal effect Effects 0.000 description 24
- 238000001514 detection method Methods 0.000 description 19
- 238000012544 monitoring process Methods 0.000 description 18
- 230000005540 biological transmission Effects 0.000 description 16
- 230000006870 function Effects 0.000 description 16
- 238000001914 filtration Methods 0.000 description 9
- 230000003287 optical effect Effects 0.000 description 8
- 230000004044 response Effects 0.000 description 6
- 230000001174 ascending effect Effects 0.000 description 4
- 238000012423 maintenance Methods 0.000 description 4
- 230000002093 peripheral effect Effects 0.000 description 4
- 238000004458 analytical method Methods 0.000 description 3
- 230000000903 blocking effect Effects 0.000 description 3
- 230000006872 improvement Effects 0.000 description 3
- 238000011068 loading method Methods 0.000 description 3
- 230000009467 reduction Effects 0.000 description 3
- 230000005856 abnormality Effects 0.000 description 2
- 239000000470 constituent Substances 0.000 description 2
- 230000007423 decrease Effects 0.000 description 2
- 238000010586 diagram Methods 0.000 description 2
- 238000012986 modification Methods 0.000 description 2
- 230000004048 modification Effects 0.000 description 2
- 241000700605 Viruses Species 0.000 description 1
- 230000002155 anti-virotic effect Effects 0.000 description 1
- 238000006243 chemical reaction Methods 0.000 description 1
- 230000006835 compression Effects 0.000 description 1
- 238000007906 compression Methods 0.000 description 1
- 238000004590 computer program Methods 0.000 description 1
- 238000011161 development Methods 0.000 description 1
- 230000000694 effects Effects 0.000 description 1
- 239000000284 extract Substances 0.000 description 1
- 238000007667 floating Methods 0.000 description 1
- 238000009434 installation Methods 0.000 description 1
- 230000007246 mechanism Effects 0.000 description 1
- 239000013585 weight reducing agent Substances 0.000 description 1
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/02—Network architectures or network communication protocols for network security for separating internal from external traffic, e.g. firewalls
- H04L63/0227—Filtering policies
- H04L63/0263—Rule management
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1408—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
- H04L63/1416—Event detection, e.g. attack signature detection
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L2101/00—Indexing scheme associated with group H04L61/00
- H04L2101/30—Types of network names
- H04L2101/345—Types of network names containing wildcard characters
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L2463/00—Additional details relating to network architectures or network communication protocols for network security covered by H04L63/00
- H04L2463/144—Detection or countermeasures against botnets
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L43/00—Arrangements for monitoring or testing data switching networks
- H04L43/08—Monitoring or testing based on specific metrics, e.g. QoS, energy consumption or environmental parameters
- H04L43/0805—Monitoring or testing based on specific metrics, e.g. QoS, energy consumption or environmental parameters by checking availability
- H04L43/0817—Monitoring or testing based on specific metrics, e.g. QoS, energy consumption or environmental parameters by checking availability by checking functioning
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L61/00—Network arrangements, protocols or services for addressing or naming
- H04L61/30—Managing network names, e.g. use of aliases or nicknames
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Business, Economics & Management (AREA)
- General Business, Economics & Management (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
- Computer And Data Communications (AREA)
Description
図1は、前提技術に係る通信制御システムの構成を示す。通信制御システム100は、通信制御装置10と、通信制御装置10の動作を支援するために設けられた各種の周辺装置を含む。前提技術の通信制御装置10は、インターネットサービスプロバイダなどにより提供されるパケットフィルタリング機能を実現する。ネットワークの経路に設けられた通信制御装置10は、ネットワークを介して送受信されるパケットを取得して、その内容を解析し、通信の許否を判断する。通信が許可される場合は、通信制御装置10は、そのパケットをネットワークへ送出する。通信が禁止される場合は、通信制御装置10は、そのパケットを破棄し、必要であれば送信元に対して警告メッセージなどを返信する。
図23は、実施の形態に係る通信管理システムの構成を示す。通信管理システム300は、パケットフィルタリングなどの機能を有する通信制御装置10を用いて、ボットを操作するための通信など、不適切な通信を検知して遮断するための処理を行う。
Claims (2)
- 正常な通信のシグネチャのリストを格納した正常シグネチャリストと、
通信データを取得し、その通信データが前記正常シグネチャリストに格納された正常な通信のシグネチャに合致するか否かを検索する第1の検索部と、
前記正常シグネチャリストに格納された正常な通信のシグネチャに合致しない通信データを検知したときに警告を発する警告部と、
通信データの中から、特定の通信データを出力させるためのルールを格納したルールデータベースと、
警告を発せられた通信データに関連した通信データを出力させるために、警告が発せられた通信データの送信元のIPアドレス、送信先のIPアドレス、又はペイロードの内容を前記ルールデータベースにルールとして登録する更新部と、
前記更新部が受け付けた前記ルールの変更を前記ルールデータベースにリアルタイムに反映させるデータベースサーバと、
通信データを取得し、その通信データが前記ルールデータベースに格納されたルールに合致するか否かを検索する第2の検索部と、
前記ルールデータベースに格納されたルールに合致する通信データを検知したときに、その通信データを複製して出力する出力部と、
を備えることを特徴とする通信管理システム。 - 上流のネットワークから通信データを取得して前記第1又は第2の検索部へ供給する第1の通信制御部と、
前記通信データを下流のネットワークへ送出する第2の通信制御部と、を更に備え、
前記出力部は、前記ルールに合致する通信データを複製して出力することを特徴とする請求項1に記載の通信管理システム。
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| PCT/JP2006/316649 WO2008023424A1 (en) | 2006-08-24 | 2006-08-24 | Communication management system and communication management method |
Publications (2)
| Publication Number | Publication Date |
|---|---|
| JPWO2008023424A1 JPWO2008023424A1 (ja) | 2010-01-07 |
| JP4574675B2 true JP4574675B2 (ja) | 2010-11-04 |
Family
ID=39106518
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| JP2007513543A Expired - Fee Related JP4574675B2 (ja) | 2006-08-24 | 2006-08-24 | 通信管理システム |
Country Status (3)
| Country | Link |
|---|---|
| US (1) | US8463727B2 (ja) |
| JP (1) | JP4574675B2 (ja) |
| WO (1) | WO2008023424A1 (ja) |
Families Citing this family (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US8665312B2 (en) * | 2010-12-06 | 2014-03-04 | Ricoh Company, Ltd. | Apparatus, system, and method of managing data transmission, and transmission management program |
| US9910904B2 (en) | 2011-08-30 | 2018-03-06 | International Business Machines Corporation | Replication of data objects from a source server to a target server |
| US8838529B2 (en) | 2011-08-30 | 2014-09-16 | International Business Machines Corporation | Applying replication rules to determine whether to replicate objects |
| CN103870291A (zh) * | 2012-12-13 | 2014-06-18 | 鸿富锦精密工业(深圳)有限公司 | 电子设备升级系统及方法 |
| US10725708B2 (en) | 2015-07-31 | 2020-07-28 | International Business Machines Corporation | Replication of versions of an object from a source storage to a target storage |
| US11916971B2 (en) * | 2022-02-01 | 2024-02-27 | Capital One Services, Llc | Updating security rule sets using repository switching |
Family Cites Families (18)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JPH04180425A (ja) | 1990-11-15 | 1992-06-26 | Toshiba Corp | 通信システム |
| JP3165366B2 (ja) | 1996-02-08 | 2001-05-14 | 株式会社日立製作所 | ネットワークセキュリティシステム |
| WO2002082750A1 (en) | 2001-04-02 | 2002-10-17 | Dcl Inc. | Bit string searching device and method |
| JP2003157190A (ja) | 2001-09-05 | 2003-05-30 | Matsushita Electric Ind Co Ltd | 同期メッセージ処理方法 |
| US20040243843A1 (en) | 2001-09-19 | 2004-12-02 | Yuri Kadobayashi | Content server defending system |
| US7093023B2 (en) | 2002-05-21 | 2006-08-15 | Washington University | Methods, systems, and devices using reprogrammable hardware for high-speed processing of streaming data to find a redefinable pattern and respond thereto |
| JP2004030286A (ja) | 2002-06-26 | 2004-01-29 | Ntt Data Corp | 侵入検知システムおよび侵入検知プログラム |
| JP4042776B2 (ja) | 2002-08-20 | 2008-02-06 | 日本電気株式会社 | 攻撃検知装置および攻撃検知方法 |
| US20050015599A1 (en) | 2003-06-25 | 2005-01-20 | Nokia, Inc. | Two-phase hash value matching technique in message protection systems |
| JP2005128933A (ja) | 2003-10-27 | 2005-05-19 | Ntt Docomo Inc | 情報処理装置、不正侵入検出方法及び不正侵入検出プログラム |
| KR100544674B1 (ko) * | 2003-11-11 | 2006-01-23 | 한국전자통신연구원 | 커널 기반의 침입탐지시스템에서의 침입탐지규칙 동적변경 방법 |
| JP2005267266A (ja) | 2004-03-18 | 2005-09-29 | Nec Corp | グループ間情報共有システム |
| JP4405360B2 (ja) | 2004-10-12 | 2010-01-27 | パナソニック株式会社 | ファイアウォールシステム及びファイアウォール制御方法 |
| EP1804447A1 (en) | 2004-10-21 | 2007-07-04 | Nippon Telegraph and Telephone Corporation | Protect device, protect method, protect program, and network attack protect system |
| JP4398354B2 (ja) * | 2004-12-20 | 2010-01-13 | 富士通株式会社 | 中継システム |
| US8396927B2 (en) | 2004-12-21 | 2013-03-12 | Alcatel Lucent | Detection of unwanted messages (spam) |
| JP4429892B2 (ja) * | 2004-12-22 | 2010-03-10 | 富士通株式会社 | セキュア通信システム、および通信経路選択装置 |
| US7979889B2 (en) * | 2005-01-07 | 2011-07-12 | Cisco Technology, Inc. | Methods and apparatus providing security to computer systems and networks |
-
2006
- 2006-08-24 US US12/438,703 patent/US8463727B2/en not_active Expired - Fee Related
- 2006-08-24 WO PCT/JP2006/316649 patent/WO2008023424A1/ja not_active Ceased
- 2006-08-24 JP JP2007513543A patent/JP4574675B2/ja not_active Expired - Fee Related
Also Published As
| Publication number | Publication date |
|---|---|
| WO2008023424A1 (en) | 2008-02-28 |
| US20100063951A1 (en) | 2010-03-11 |
| US8463727B2 (en) | 2013-06-11 |
| JPWO2008023424A1 (ja) | 2010-01-07 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| JP4015690B1 (ja) | 通信管理システム、通信管理方法、及び通信制御装置 | |
| JP4554671B2 (ja) | 通信制御装置 | |
| JP4554675B2 (ja) | 通信制御装置及び通信制御システム | |
| JP4087427B2 (ja) | データ処理システム | |
| JP4571184B2 (ja) | 通信管理システム | |
| JP4574675B2 (ja) | 通信管理システム | |
| JP4188409B2 (ja) | 通信管理システム、通信管理方法、及び通信制御装置 | |
| JP4146505B1 (ja) | 判定装置及び判定方法 | |
| JP4319246B2 (ja) | 通信制御装置及び通信制御方法 | |
| JPWO2009066343A1 (ja) | 通信制御装置及び通信制御方法 | |
| JP4676530B2 (ja) | 通信制御装置 | |
| JPWO2008075426A1 (ja) | 通信制御装置及び通信制御方法 | |
| JP5156892B2 (ja) | ログ出力制御装置及びログ出力制御方法 | |
| JP4638513B2 (ja) | 通信制御装置及び通信制御方法 | |
| JP5380710B2 (ja) | 通信制御装置 | |
| JPWO2009066347A1 (ja) | 負荷分散装置 | |
| KR20080017046A (ko) | 데이터 프로세싱 시스템 | |
| KR20080057284A (ko) | 통신 관리 시스템, 통신 관리 방법, 및 통신 제어 장치 | |
| JPWO2009066341A1 (ja) | 検知回路及び検知方法 | |
| JPWO2009069178A1 (ja) | 通信制御装置及び通信制御方法 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| A02 | Decision of refusal |
Free format text: JAPANESE INTERMEDIATE CODE: A02 Effective date: 20071204 |
|
| A01 | Written decision to grant a patent or to grant a registration (utility model) |
Free format text: JAPANESE INTERMEDIATE CODE: A01 |
|
| A61 | First payment of annual fees (during grant procedure) |
Free format text: JAPANESE INTERMEDIATE CODE: A61 Effective date: 20100818 |
|
| R150 | Certificate of patent or registration of utility model |
Free format text: JAPANESE INTERMEDIATE CODE: R150 |
|
| FPAY | Renewal fee payment (event date is renewal date of database) |
Free format text: PAYMENT UNTIL: 20130827 Year of fee payment: 3 |
|
| S531 | Written request for registration of change of domicile |
Free format text: JAPANESE INTERMEDIATE CODE: R313531 |
|
| R360 | Written notification for declining of transfer of rights |
Free format text: JAPANESE INTERMEDIATE CODE: R360 |
|
| S531 | Written request for registration of change of domicile |
Free format text: JAPANESE INTERMEDIATE CODE: R313531 |
|
| R370 | Written measure of declining of transfer procedure |
Free format text: JAPANESE INTERMEDIATE CODE: R370 |
|
| R350 | Written notification of registration of transfer |
Free format text: JAPANESE INTERMEDIATE CODE: R350 |
|
| R250 | Receipt of annual fees |
Free format text: JAPANESE INTERMEDIATE CODE: R250 |
|
| R250 | Receipt of annual fees |
Free format text: JAPANESE INTERMEDIATE CODE: R250 |
|
| R250 | Receipt of annual fees |
Free format text: JAPANESE INTERMEDIATE CODE: R250 |
|
| R250 | Receipt of annual fees |
Free format text: JAPANESE INTERMEDIATE CODE: R250 |
|
| S531 | Written request for registration of change of domicile |
Free format text: JAPANESE INTERMEDIATE CODE: R313531 |
|
| R350 | Written notification of registration of transfer |
Free format text: JAPANESE INTERMEDIATE CODE: R350 |
|
| R250 | Receipt of annual fees |
Free format text: JAPANESE INTERMEDIATE CODE: R250 |
|
| LAPS | Cancellation because of no payment of annual fees |