Presentation is loading. Please wait.

Presentation is loading. Please wait.

1 CURELAN TECHNOLOGY Co., LTD Flowviewer FM-800A CURELAN TECHNOLOGY Co., LTD www.CureLan.com.

Similar presentations


Presentation on theme: "1 CURELAN TECHNOLOGY Co., LTD Flowviewer FM-800A CURELAN TECHNOLOGY Co., LTD www.CureLan.com."— Presentation transcript:

1 1 CURELAN TECHNOLOGY Co., LTD Flowviewer FM-800A CURELAN TECHNOLOGY Co., LTD www.CureLan.com

2 Slow response time Do Hackers Attack ? 2

3 Why do Hackers Attack ? Steal private data & credit card info 3

4 The Blind Spot of the IPS Equipment Feature code scheme (pattern) High error rate on the threshold setting function False Positives 4

5 Cyber-Intrusion== Cyber-Attack Cyber-Intrusion V.S. Attack Robber Huge Traffic / Sessions Not care being discovered 5 Cyber-Intrusion Cyber-Attack Thief Small packet Not like to be discovered

6 The Blind Spot of the IPS Equipment The Amount of TrafficA Number of Sessions

7 Network Behavior Anomaly Detection (NBAD) Detect & block attacks automatically 7 NBAD Technology Flowviewer is 64 bit solution NBAD Technology Flowviewer is 64 bit solution Picture provided by : free vector graphics Version 1 Version 2 ? TRUE ? FALSE ? High Error Rate High Error Rate

8 Packets Sessions (Flows) Protocol Transport protocol port Time Duration Destination IP address Source IP address Traffic Info Collected Real-Time Data Collected From The Flowviewer FM-800A

9 Intrusion Port scan SSH RDP Worm Attack UDP Flood Attack DOS Attack DNS Attack NTP Attack Detect and Block Intrusion & Attack

10 Math Formula 10 S: session P src n : source port number P dst n : destination port number T n : some time ∵ ∵

11 IPS ( Intrusion prevention system ) of DoS Protection Profile Threshold Function UDP_SRC_Session default 5,000 session/ second UDP_DST_Session default 5,000 session/ second UDP_Flood default 2,000 packets/ second 11

12 Real Case 1 A University: Event Time, 2014 / 05 / 27 05:00-06:00 12

13 IPS Threshold : default 5,000 session / sec Hacker can avoid IPS detection 13 The maximum session of attack is 743. Hacker can avoid IPS detection.

14 Real Case 2 B University: Event Time, 2015 / 07 / 21 22:00-23:00 14

15 IPS Threshold : default 5,000 session / sec Hacker can avoid IPS detection 15 The maximum session of attack is 2327. Hacker can avoid IPS detection.


Download ppt "1 CURELAN TECHNOLOGY Co., LTD Flowviewer FM-800A CURELAN TECHNOLOGY Co., LTD www.CureLan.com."

Similar presentations


Ads by Google