To provide a network monitoring system capable of discovering unknown illegal program activity in its early stages.
An application specifying part 221 specifies a transmission application about a packet extracted by an interface 210, a header analysis extracting part 222 analyzes header information and a band analyzing part 223 further analyzes a communication band in accordance with these analysis results. The analysis results are stored in a database 230 and statistically processed by an output processing part 240. Since analysis can be performed for each application, illegal activity that is performed by an unknown or existing illegal program by using the existing application can be discovered in its early stages.
COPYRIGHT: (C)2007,JPO&INPIT
JP2004328307A | ||||
JP2005184792A | ||||
JP2005134974A | ||||
JP2004229091A | ||||
JP2002164890A |