The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Jul. 06, 2021

Filed:

Nov. 27, 2018
Applicant:

Institute for Information Industry, Taipei, TW;

Inventors:

Chi-Kuan Chiu, Taoyuan, TW;

Hsiao-Hsien Chang, Taipei, TW;

Te-En Wei, Taipei, TW;

Assignee:
Attorney:
Primary Examiner:
Int. Cl.
CPC ...
H04L 29/06 (2006.01); G06F 16/955 (2019.01); G06K 9/62 (2006.01); G06N 20/00 (2019.01); G06F 16/906 (2019.01);
U.S. Cl.
CPC ...
H04L 63/1416 (2013.01); G06F 16/906 (2019.01); G06F 16/955 (2019.01); G06K 9/6218 (2013.01); G06N 20/00 (2019.01); H04L 63/14 (2013.01); H04L 63/1441 (2013.01); H04L 69/22 (2013.01);
Abstract

A suspicious packet detection device and a suspicious packet detection method thereof are provided. The suspicious packet detection device captures an HTTP packet transmitted from an internal network to an external network, and based on an HTTP header of the HTTP packet, determines that the HTTP packet belongs to one of a browser category and an application category and identifies the HTTP packet as one of a normal packet and a suspicious packet. When the HTTP packet is identified as the normal packet, the suspicious packet detection device further verifies whether the HTTP packet is the suspicious packet or not by comparing the HTTP header with relevance information or by using a URL classification model.


Find Patent Forward Citations

Loading…