CN101282340A - 网络攻击处理方法及处理装置 - Google Patents
网络攻击处理方法及处理装置 Download PDFInfo
- Publication number
- CN101282340A CN101282340A CNA2008100961836A CN200810096183A CN101282340A CN 101282340 A CN101282340 A CN 101282340A CN A2008100961836 A CNA2008100961836 A CN A2008100961836A CN 200810096183 A CN200810096183 A CN 200810096183A CN 101282340 A CN101282340 A CN 101282340A
- Authority
- CN
- China
- Prior art keywords
- attack
- main frame
- target
- network
- control
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Granted
Links
- 238000000034 method Methods 0.000 title abstract description 8
- 238000004891 communication Methods 0.000 claims abstract description 19
- 238000003672 processing method Methods 0.000 claims abstract description 15
- 238000012876 topography Methods 0.000 claims description 18
- 238000004458 analytical method Methods 0.000 claims description 12
- 230000001143 conditioned effect Effects 0.000 claims description 2
- 230000008520 organization Effects 0.000 abstract 1
- 238000012098 association analyses Methods 0.000 description 5
- 238000005516 engineering process Methods 0.000 description 5
- 238000004140 cleaning Methods 0.000 description 3
- 238000010276 construction Methods 0.000 description 3
- 238000001514 detection method Methods 0.000 description 3
- 230000002159 abnormal effect Effects 0.000 description 2
- 230000032683 aging Effects 0.000 description 2
- 230000002547 anomalous effect Effects 0.000 description 2
- 230000008878 coupling Effects 0.000 description 2
- 238000010168 coupling process Methods 0.000 description 2
- 238000005859 coupling reaction Methods 0.000 description 2
- 230000001419 dependent effect Effects 0.000 description 2
- 238000010586 diagram Methods 0.000 description 2
- 230000015572 biosynthetic process Effects 0.000 description 1
- 230000001186 cumulative effect Effects 0.000 description 1
- 238000001914 filtration Methods 0.000 description 1
- 239000000203 mixture Substances 0.000 description 1
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1441—Countermeasures against malicious traffic
- H04L63/1458—Denial of Service
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1408—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
- H04L63/1416—Event detection, e.g. attack signature detection
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
Description
目的IP | 源IP | 目的端口 | 源端口 | 协议类型 | 发包频率 | 累计数量 |
目的IP | 源IP | 目的端口 | 源端口 | 协议类型 | 连接频率 | 累计数量 |
目的IP | 源IP | 目的端口 | 源端口 | 协议类型 | DDOS名称 | 攻击类型 | 触犯规则 |
目的IP | 源IP | 目的端口 | 源端口 | 协议类型 | DDOS名称 | 控制类型 | 触犯规则 |
目的端口 | 源端口 | 协议类型 | 流量数值 | 当前阈值 | 动作标记 | 异常类别 |
Claims (11)
Priority Applications (3)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN2008100961836A CN101282340B (zh) | 2008-05-09 | 2008-05-09 | 网络攻击处理方法及处理装置 |
PCT/CN2009/071020 WO2009135396A1 (zh) | 2008-05-09 | 2009-03-26 | 网络攻击处理方法、处理装置及网络分析监控中心 |
US12/435,001 US20090282478A1 (en) | 2008-05-09 | 2009-05-04 | Method and apparatus for processing network attack |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN2008100961836A CN101282340B (zh) | 2008-05-09 | 2008-05-09 | 网络攻击处理方法及处理装置 |
Publications (2)
Publication Number | Publication Date |
---|---|
CN101282340A true CN101282340A (zh) | 2008-10-08 |
CN101282340B CN101282340B (zh) | 2010-09-22 |
Family
ID=40014615
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN2008100961836A Expired - Fee Related CN101282340B (zh) | 2008-05-09 | 2008-05-09 | 网络攻击处理方法及处理装置 |
Country Status (3)
Country | Link |
---|---|
US (1) | US20090282478A1 (zh) |
CN (1) | CN101282340B (zh) |
WO (1) | WO2009135396A1 (zh) |
Cited By (12)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
WO2009135396A1 (zh) * | 2008-05-09 | 2009-11-12 | 成都市华为赛门铁克科技有限公司 | 网络攻击处理方法、处理装置及网络分析监控中心 |
WO2011047600A1 (zh) * | 2009-10-20 | 2011-04-28 | 成都市华为赛门铁克科技有限公司 | 僵尸网络检测方法、装置和系统 |
EP2448211A1 (en) * | 2009-07-29 | 2012-05-02 | Chengdu Huawei Symantec Technologies Co., Ltd | Method, system and equipment for detecting botnets |
CN105282152A (zh) * | 2015-09-28 | 2016-01-27 | 广东睿江科技有限公司 | 一种异常流量检测的方法 |
CN106060045A (zh) * | 2016-05-31 | 2016-10-26 | 东北大学 | 面向带宽消耗型攻击的过滤位置选择方法 |
CN107104920A (zh) * | 2016-02-19 | 2017-08-29 | 阿里巴巴集团控股有限公司 | 用于识别中控机的方法及装置 |
CN108768917A (zh) * | 2017-08-23 | 2018-11-06 | 长安通信科技有限责任公司 | 一种基于网络日志的僵尸网络检测方法及系统 |
CN109194680A (zh) * | 2018-09-27 | 2019-01-11 | 腾讯科技(深圳)有限公司 | 一种网络攻击识别方法、装置及设备 |
CN110198319A (zh) * | 2019-06-03 | 2019-09-03 | 电子科技大学 | 基于多反例的安全协议漏洞挖掘方法 |
CN110611673A (zh) * | 2019-09-18 | 2019-12-24 | 赛尔网络有限公司 | Ip信用计算方法、装置、电子设备及介质 |
CN113709130A (zh) * | 2021-08-20 | 2021-11-26 | 江苏通付盾科技有限公司 | 基于蜜罐系统的风险识别方法及装置 |
CN114039772A (zh) * | 2021-11-08 | 2022-02-11 | 北京天融信网络安全技术有限公司 | 针对网络攻击的检测方法及电子设备 |
Families Citing this family (15)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US20100332641A1 (en) * | 2007-11-09 | 2010-12-30 | Kulesh Shanmugasundaram | Passive detection of rebooting hosts in a network |
KR20120072266A (ko) * | 2010-12-23 | 2012-07-03 | 한국전자통신연구원 | 전역 네트워크 보안상황 제어 장치 및 방법 |
KR101036750B1 (ko) * | 2011-01-04 | 2011-05-23 | 주식회사 엔피코어 | 좀비행위 차단 시스템 및 방법 |
US9088606B2 (en) * | 2012-07-05 | 2015-07-21 | Tenable Network Security, Inc. | System and method for strategic anti-malware monitoring |
CN104601526B (zh) * | 2013-10-31 | 2018-01-09 | 华为技术有限公司 | 一种冲突检测及解决的方法、装置 |
US10454950B1 (en) * | 2015-06-30 | 2019-10-22 | Fireeye, Inc. | Centralized aggregation technique for detecting lateral movement of stealthy cyber-attacks |
US10826933B1 (en) | 2016-03-31 | 2020-11-03 | Fireeye, Inc. | Technique for verifying exploit/malware at malware detection appliance through correlation with endpoints |
US10893059B1 (en) | 2016-03-31 | 2021-01-12 | Fireeye, Inc. | Verification and enhancement using detection systems located at the network periphery and endpoint devices |
CN107104951B (zh) * | 2017-03-29 | 2020-06-19 | 国家电网公司 | 网络攻击源的检测方法和装置 |
CN108540441A (zh) * | 2018-02-07 | 2018-09-14 | 广州锦行网络科技有限公司 | 一种基于真实性虚拟网络的主动防御系统及方法 |
CN111641951B (zh) * | 2020-04-30 | 2023-10-24 | 中国移动通信集团有限公司 | 一种基于sa架构的5g网络apt攻击溯源方法及系统 |
CN111740855B (zh) * | 2020-05-06 | 2023-04-18 | 首都师范大学 | 基于数据迁移的风险识别方法、装置、设备及存储介质 |
DE102020209993A1 (de) * | 2020-08-06 | 2022-02-10 | Robert Bosch Gesellschaft mit beschränkter Haftung | Verfahren und Vorrichtung zur Verarbeitung von Daten eines technischen Systems |
CN113904866B (zh) * | 2021-10-29 | 2024-02-09 | 中国电信股份有限公司 | Sd-wan业务流量安全处置引流方法、设备、系统以及介质 |
CN114363002B (zh) * | 2021-12-07 | 2023-06-09 | 绿盟科技集团股份有限公司 | 一种网络攻击关系图的生成方法及装置 |
Family Cites Families (14)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US7168093B2 (en) * | 2001-01-25 | 2007-01-23 | Solutionary, Inc. | Method and apparatus for verifying the integrity and security of computer networks and implementation of counter measures |
US7603709B2 (en) * | 2001-05-03 | 2009-10-13 | Computer Associates Think, Inc. | Method and apparatus for predicting and preventing attacks in communications networks |
US7107619B2 (en) * | 2001-08-31 | 2006-09-12 | International Business Machines Corporation | System and method for the detection of and reaction to denial of service attacks |
US20030065943A1 (en) * | 2001-09-28 | 2003-04-03 | Christoph Geis | Method and apparatus for recognizing and reacting to denial of service attacks on a computerized network |
KR100468232B1 (ko) * | 2002-02-19 | 2005-01-26 | 한국전자통신연구원 | 분산된 침입탐지 에이전트와 관리자 시스템을 이용한네트워크 기반 침입자 역추적 시스템 및 그 방법 |
CN100370757C (zh) * | 2004-07-09 | 2008-02-20 | 国际商业机器公司 | 识别网络内分布式拒绝服务攻击和防御攻击的方法和系统 |
US8423645B2 (en) * | 2004-09-14 | 2013-04-16 | International Business Machines Corporation | Detection of grid participation in a DDoS attack |
US7454790B2 (en) * | 2005-05-23 | 2008-11-18 | Ut-Battelle, Llc | Method for detecting sophisticated cyber attacks |
US8161555B2 (en) * | 2005-06-28 | 2012-04-17 | At&T Intellectual Property Ii, L.P. | Progressive wiretap |
CN1777182A (zh) * | 2005-12-06 | 2006-05-24 | 南京邮电大学 | 一种基于洪泛攻击的高效、安全追踪方案 |
KR100951770B1 (ko) * | 2005-12-30 | 2010-04-08 | 경희대학교 산학협력단 | IPv6 네트워크에서 IP를 역추적하는 방법 |
KR100770354B1 (ko) * | 2006-08-03 | 2007-10-26 | 경희대학교 산학협력단 | IPv6 네트워크에서 공격자 호스트의 IP를 역추적하는방법 |
CN1997023B (zh) * | 2006-12-19 | 2011-04-27 | 中国科学院研究生院 | 用于ip追踪的内部边采样方法和系统 |
CN101282340B (zh) * | 2008-05-09 | 2010-09-22 | 成都市华为赛门铁克科技有限公司 | 网络攻击处理方法及处理装置 |
-
2008
- 2008-05-09 CN CN2008100961836A patent/CN101282340B/zh not_active Expired - Fee Related
-
2009
- 2009-03-26 WO PCT/CN2009/071020 patent/WO2009135396A1/zh active Application Filing
- 2009-05-04 US US12/435,001 patent/US20090282478A1/en not_active Abandoned
Cited By (21)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
WO2009135396A1 (zh) * | 2008-05-09 | 2009-11-12 | 成都市华为赛门铁克科技有限公司 | 网络攻击处理方法、处理装置及网络分析监控中心 |
EP2448211A1 (en) * | 2009-07-29 | 2012-05-02 | Chengdu Huawei Symantec Technologies Co., Ltd | Method, system and equipment for detecting botnets |
EP2448211A4 (en) * | 2009-07-29 | 2012-05-02 | Chengdu Huawei Symantec Tech | METHOD, SYSTEM AND EQUIPMENT FOR RECOGNIZING BOTNET NETWORKS |
WO2011047600A1 (zh) * | 2009-10-20 | 2011-04-28 | 成都市华为赛门铁克科技有限公司 | 僵尸网络检测方法、装置和系统 |
US8904532B2 (en) | 2009-10-20 | 2014-12-02 | Chengdu Huawei Symantec Technologies Co., Ltd. | Method, apparatus and system for detecting botnet |
CN105282152A (zh) * | 2015-09-28 | 2016-01-27 | 广东睿江科技有限公司 | 一种异常流量检测的方法 |
CN105282152B (zh) * | 2015-09-28 | 2018-08-28 | 广东睿江云计算股份有限公司 | 一种异常流量检测的方法 |
CN107104920B (zh) * | 2016-02-19 | 2020-09-29 | 阿里巴巴集团控股有限公司 | 用于识别中控机的方法及装置 |
CN107104920A (zh) * | 2016-02-19 | 2017-08-29 | 阿里巴巴集团控股有限公司 | 用于识别中控机的方法及装置 |
CN106060045A (zh) * | 2016-05-31 | 2016-10-26 | 东北大学 | 面向带宽消耗型攻击的过滤位置选择方法 |
CN106060045B (zh) * | 2016-05-31 | 2019-12-06 | 东北大学 | 面向带宽消耗型攻击的过滤位置选择方法 |
CN108768917A (zh) * | 2017-08-23 | 2018-11-06 | 长安通信科技有限责任公司 | 一种基于网络日志的僵尸网络检测方法及系统 |
CN108768917B (zh) * | 2017-08-23 | 2021-05-11 | 长安通信科技有限责任公司 | 一种基于网络日志的僵尸网络检测方法及系统 |
CN109194680A (zh) * | 2018-09-27 | 2019-01-11 | 腾讯科技(深圳)有限公司 | 一种网络攻击识别方法、装置及设备 |
CN109194680B (zh) * | 2018-09-27 | 2021-02-12 | 腾讯科技(深圳)有限公司 | 一种网络攻击识别方法、装置及设备 |
CN110198319A (zh) * | 2019-06-03 | 2019-09-03 | 电子科技大学 | 基于多反例的安全协议漏洞挖掘方法 |
CN110611673A (zh) * | 2019-09-18 | 2019-12-24 | 赛尔网络有限公司 | Ip信用计算方法、装置、电子设备及介质 |
CN110611673B (zh) * | 2019-09-18 | 2021-08-31 | 赛尔网络有限公司 | Ip信用计算方法、装置、电子设备及介质 |
CN113709130A (zh) * | 2021-08-20 | 2021-11-26 | 江苏通付盾科技有限公司 | 基于蜜罐系统的风险识别方法及装置 |
CN114039772A (zh) * | 2021-11-08 | 2022-02-11 | 北京天融信网络安全技术有限公司 | 针对网络攻击的检测方法及电子设备 |
CN114039772B (zh) * | 2021-11-08 | 2023-11-28 | 北京天融信网络安全技术有限公司 | 针对网络攻击的检测方法及电子设备 |
Also Published As
Publication number | Publication date |
---|---|
CN101282340B (zh) | 2010-09-22 |
WO2009135396A1 (zh) | 2009-11-12 |
US20090282478A1 (en) | 2009-11-12 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
CN101282340B (zh) | 网络攻击处理方法及处理装置 | |
CN101309150B (zh) | 分布式拒绝服务攻击的防御方法、装置和系统 | |
CN107231384B (zh) | 一种面向5g网络切片的DDoS攻击检测防御方法及系统 | |
KR100748246B1 (ko) | 침입탐지 로그수집 엔진과 트래픽 통계수집 엔진을 이용한다단계 통합보안 관리 시스템 및 방법 | |
CN101431449B (zh) | 一种网络流量清洗系统 | |
CN105208037B (zh) | 一种基于轻量级入侵检测的DoS/DDoS攻击检测和过滤方法 | |
CN101980506B (zh) | 一种基于流量特征分析的分布式入侵检测方法 | |
CN102821002B (zh) | 网络流量异常检测方法和系统 | |
CN1160899C (zh) | 分布式网络动态安全保护系统 | |
CN104202336A (zh) | 一种基于信息熵的DDoS攻击检测方法 | |
CN104618377B (zh) | 基于NetFlow的僵尸网络检测系统与检测方法 | |
CN101547187B (zh) | 宽带接入设备的网络攻击防护方法 | |
US20040255162A1 (en) | Security gateway system and method for intrusion detection | |
CN108282497A (zh) | 针对SDN控制平面的DDoS攻击检测方法 | |
CN103607399A (zh) | 基于暗网的专用ip网络安全监测系统及方法 | |
CN104683346A (zh) | 基于流量分析的p2p僵尸网络检测装置及方法 | |
CN113037567B (zh) | 一种用于电网企业的网络攻击行为仿真系统的仿真方法 | |
CN105187437A (zh) | 一种sdn网络拒绝服务攻击的集中式检测系统 | |
CN111786986B (zh) | 一种数控系统网络入侵防范系统及方法 | |
CN106209902A (zh) | 一种应用于知识产权运营平台的网络安全系统及检测方法 | |
CN101202744A (zh) | 一种自学习检测蠕虫的装置及其方法 | |
CN106685962A (zh) | 一种反射型ddos攻击流量的防御系统及方法 | |
CN113162939A (zh) | 一种基于改进k近邻算法的SDN下DDoS攻击的检测防御系统 | |
CN103957128A (zh) | 云计算环境下监控数据流向的方法及系统 | |
CN103139206B (zh) | 一种僵尸主机的检测方法及装置 |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
C06 | Publication | ||
PB01 | Publication | ||
C10 | Entry into substantive examination | ||
SE01 | Entry into force of request for substantive examination | ||
ASS | Succession or assignment of patent right |
Owner name: CHENGDU CITY HUAWEI SAIMENTEKE SCIENCE CO., LTD. Free format text: FORMER OWNER: HUAWEI TECHNOLOGY CO., LTD. Effective date: 20090424 |
|
C41 | Transfer of patent application or patent right or utility model | ||
TA01 | Transfer of patent application right |
Effective date of registration: 20090424 Address after: Qingshui River District, Chengdu high tech Zone, Sichuan Province, China: 611731 Applicant after: CHENGDU HUAWEI SYMANTEC TECHNOLOGIES Co.,Ltd. Address before: Bantian HUAWEI headquarters office building, Longgang District, Guangdong, Shenzhen Province, China: 518129 Applicant before: HUAWEI TECHNOLOGIES Co.,Ltd. |
|
C14 | Grant of patent or utility model | ||
GR01 | Patent grant | ||
C56 | Change in the name or address of the patentee |
Owner name: HUAWEI DIGITAL TECHNOLOGY (CHENGDU) CO., LTD. Free format text: FORMER NAME: CHENGDU HUAWEI SYMANTEC TECHNOLOGIES CO., LTD. |
|
CP01 | Change in the name or title of a patent holder |
Address after: 611731 Chengdu high tech Zone, Sichuan, West Park, Qingshui River Patentee after: HUAWEI DIGITAL TECHNOLOGIES (CHENG DU) Co.,Ltd. Address before: 611731 Chengdu high tech Zone, Sichuan, West Park, Qingshui River Patentee before: CHENGDU HUAWEI SYMANTEC TECHNOLOGIES Co.,Ltd. |
|
TR01 | Transfer of patent right | ||
TR01 | Transfer of patent right |
Effective date of registration: 20220826 Address after: No. 1899 Xiyuan Avenue, high tech Zone (West District), Chengdu, Sichuan 610041 Patentee after: Chengdu Huawei Technologies Co.,Ltd. Address before: 611731 Qingshui River District, Chengdu hi tech Zone, Sichuan, China Patentee before: HUAWEI DIGITAL TECHNOLOGIES (CHENG DU) Co.,Ltd. |
|
CF01 | Termination of patent right due to non-payment of annual fee |
Granted publication date: 20100922 |