CN105656693A - 一种基于回归的信息安全异常检测的方法及系统 - Google Patents
一种基于回归的信息安全异常检测的方法及系统 Download PDFInfo
- Publication number
- CN105656693A CN105656693A CN201610145683.9A CN201610145683A CN105656693A CN 105656693 A CN105656693 A CN 105656693A CN 201610145683 A CN201610145683 A CN 201610145683A CN 105656693 A CN105656693 A CN 105656693A
- Authority
- CN
- China
- Prior art keywords
- anomaly detection
- regression
- alarm
- module
- time
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Granted
Links
- 238000001514 detection method Methods 0.000 title claims abstract description 89
- 238000000034 method Methods 0.000 claims description 21
- 230000005856 abnormality Effects 0.000 claims description 3
- 238000012545 processing Methods 0.000 claims description 3
- ZXQYGBMAQZUVMI-GCMPRSNUSA-N gamma-cyhalothrin Chemical compound CC1(C)[C@@H](\C=C(/Cl)C(F)(F)F)[C@H]1C(=O)O[C@H](C#N)C1=CC=CC(OC=2C=CC=CC=2)=C1 ZXQYGBMAQZUVMI-GCMPRSNUSA-N 0.000 description 35
- 238000001914 filtration Methods 0.000 description 25
- 238000009826 distribution Methods 0.000 description 20
- 238000004458 analytical method Methods 0.000 description 13
- 238000005311 autocorrelation function Methods 0.000 description 13
- 238000004422 calculation algorithm Methods 0.000 description 12
- 230000006399 behavior Effects 0.000 description 7
- 239000006185 dispersion Substances 0.000 description 7
- 238000010586 diagram Methods 0.000 description 6
- 238000012423 maintenance Methods 0.000 description 6
- 230000006798 recombination Effects 0.000 description 5
- 238000005215 recombination Methods 0.000 description 5
- 230000011218 segmentation Effects 0.000 description 5
- 230000002123 temporal effect Effects 0.000 description 5
- 230000002159 abnormal effect Effects 0.000 description 4
- 230000001419 dependent effect Effects 0.000 description 4
- 238000007781 pre-processing Methods 0.000 description 4
- 241001123248 Arma Species 0.000 description 3
- 238000012417 linear regression Methods 0.000 description 3
- 230000000737 periodic effect Effects 0.000 description 3
- 230000001932 seasonal effect Effects 0.000 description 3
- 241000258937 Hemiptera Species 0.000 description 2
- 238000004891 communication Methods 0.000 description 2
- 230000000875 corresponding effect Effects 0.000 description 2
- 239000000284 extract Substances 0.000 description 2
- 238000004519 manufacturing process Methods 0.000 description 2
- YHXISWVBGDMDLQ-UHFFFAOYSA-N moclobemide Chemical compound C1=CC(Cl)=CC=C1C(=O)NCCN1CCOCC1 YHXISWVBGDMDLQ-UHFFFAOYSA-N 0.000 description 2
- 241000764238 Isis Species 0.000 description 1
- 206010033799 Paralysis Diseases 0.000 description 1
- 241000700605 Viruses Species 0.000 description 1
- 102100029469 WD repeat and HMG-box DNA-binding protein 1 Human genes 0.000 description 1
- 101710097421 WD repeat and HMG-box DNA-binding protein 1 Proteins 0.000 description 1
- 238000009825 accumulation Methods 0.000 description 1
- 230000032683 aging Effects 0.000 description 1
- 238000013459 approach Methods 0.000 description 1
- 238000004364 calculation method Methods 0.000 description 1
- 230000008859 change Effects 0.000 description 1
- 238000010276 construction Methods 0.000 description 1
- 230000002596 correlated effect Effects 0.000 description 1
- 238000010219 correlation analysis Methods 0.000 description 1
- 230000007547 defect Effects 0.000 description 1
- 238000013461 design Methods 0.000 description 1
- 238000011161 development Methods 0.000 description 1
- 230000018109 developmental process Effects 0.000 description 1
- 230000000694 effects Effects 0.000 description 1
- 230000008030 elimination Effects 0.000 description 1
- 238000003379 elimination reaction Methods 0.000 description 1
- 238000011156 evaluation Methods 0.000 description 1
- 238000000605 extraction Methods 0.000 description 1
- 238000000691 measurement method Methods 0.000 description 1
- 239000002184 metal Substances 0.000 description 1
- 238000012986 modification Methods 0.000 description 1
- 230000004048 modification Effects 0.000 description 1
- 238000010606 normalization Methods 0.000 description 1
- 239000002245 particle Substances 0.000 description 1
- 230000008569 process Effects 0.000 description 1
- 230000000750 progressive effect Effects 0.000 description 1
- 230000009467 reduction Effects 0.000 description 1
- 238000007619 statistical method Methods 0.000 description 1
- 238000013179 statistical model Methods 0.000 description 1
- 238000003860 storage Methods 0.000 description 1
- 230000009897 systematic effect Effects 0.000 description 1
- 238000012731 temporal analysis Methods 0.000 description 1
- 238000012360 testing method Methods 0.000 description 1
- 238000000700 time series analysis Methods 0.000 description 1
- 230000003442 weekly effect Effects 0.000 description 1
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L41/00—Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
- H04L41/06—Management of faults, events, alarms or notifications
- H04L41/0604—Management of faults, events, alarms or notifications using filtering, e.g. reduction of information by using priority, element types, position or time
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L41/00—Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
- H04L41/06—Management of faults, events, alarms or notifications
- H04L41/0631—Management of faults, events, alarms or notifications using root cause analysis; using analysis of correlation between notifications, alarms or events based on decision criteria, e.g. hierarchy, tree or time analysis
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L41/00—Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
- H04L41/06—Management of faults, events, alarms or notifications
- H04L41/0631—Management of faults, events, alarms or notifications using root cause analysis; using analysis of correlation between notifications, alarms or events based on decision criteria, e.g. hierarchy, tree or time analysis
- H04L41/064—Management of faults, events, alarms or notifications using root cause analysis; using analysis of correlation between notifications, alarms or events based on decision criteria, e.g. hierarchy, tree or time analysis involving time analysis
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1408—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
- H04L63/1416—Event detection, e.g. attack signature detection
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1408—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
- H04L63/1425—Traffic logging, e.g. anomaly detection
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Alarm Systems (AREA)
Abstract
Description
Claims (2)
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201610145683.9A CN105656693B (zh) | 2016-03-15 | 2016-03-15 | 一种基于回归的信息安全异常检测的方法及系统 |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201610145683.9A CN105656693B (zh) | 2016-03-15 | 2016-03-15 | 一种基于回归的信息安全异常检测的方法及系统 |
Publications (2)
Publication Number | Publication Date |
---|---|
CN105656693A true CN105656693A (zh) | 2016-06-08 |
CN105656693B CN105656693B (zh) | 2019-06-07 |
Family
ID=56493586
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN201610145683.9A Active CN105656693B (zh) | 2016-03-15 | 2016-03-15 | 一种基于回归的信息安全异常检测的方法及系统 |
Country Status (1)
Country | Link |
---|---|
CN (1) | CN105656693B (zh) |
Cited By (8)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN108259202A (zh) * | 2016-12-29 | 2018-07-06 | 航天信息股份有限公司 | 一种ca监测预警方法和ca监测预警系统 |
CN109444232A (zh) * | 2018-12-26 | 2019-03-08 | 苏州同阳科技发展有限公司 | 一种多通道智能化污染气体监测装置与扩散溯源方法 |
CN110519266A (zh) * | 2019-08-27 | 2019-11-29 | 四川长虹电器股份有限公司 | 一种基于统计学方法的cc攻击检测的方法 |
CN112118141A (zh) * | 2020-09-21 | 2020-12-22 | 中山大学 | 面向通信网络的告警事件关联压缩方法及装置 |
EP3696025A4 (en) * | 2017-10-13 | 2021-03-17 | Hitachi Automotive Systems, Ltd. | VEHICLE CONTROL DEVICE |
CN112785142A (zh) * | 2021-01-19 | 2021-05-11 | 翰克偲诺水务集团有限公司 | 物联网污水处理设备预警智慧工单方法及其系统 |
CN113552856A (zh) * | 2021-09-22 | 2021-10-26 | 成都数之联科技有限公司 | 工艺参数根因定位方法和相关装置 |
CN117473435A (zh) * | 2023-07-21 | 2024-01-30 | 南京审计大学 | 一种基于时空特征的突发公共卫生事件虚假异常信息检测方法 |
Citations (4)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN103441982A (zh) * | 2013-06-24 | 2013-12-11 | 杭州师范大学 | 一种基于相对熵的入侵报警分析方法 |
CN104601604A (zh) * | 2014-06-12 | 2015-05-06 | 国家电网公司 | 网络安全态势分析方法 |
US20150304346A1 (en) * | 2011-08-19 | 2015-10-22 | Korea University Research And Business Foundation | Apparatus and method for detecting anomaly of network |
CN105357063A (zh) * | 2015-12-14 | 2016-02-24 | 成都为帆斯通科技有限公司 | 一种网络空间安全态势实时检测方法 |
-
2016
- 2016-03-15 CN CN201610145683.9A patent/CN105656693B/zh active Active
Patent Citations (4)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US20150304346A1 (en) * | 2011-08-19 | 2015-10-22 | Korea University Research And Business Foundation | Apparatus and method for detecting anomaly of network |
CN103441982A (zh) * | 2013-06-24 | 2013-12-11 | 杭州师范大学 | 一种基于相对熵的入侵报警分析方法 |
CN104601604A (zh) * | 2014-06-12 | 2015-05-06 | 国家电网公司 | 网络安全态势分析方法 |
CN105357063A (zh) * | 2015-12-14 | 2016-02-24 | 成都为帆斯通科技有限公司 | 一种网络空间安全态势实时检测方法 |
Non-Patent Citations (1)
Title |
---|
邹柏贤: ""网络异常的检测与诊断方法"", 《小型微型计算机系统》 * |
Cited By (14)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN108259202A (zh) * | 2016-12-29 | 2018-07-06 | 航天信息股份有限公司 | 一种ca监测预警方法和ca监测预警系统 |
US11580223B2 (en) | 2017-10-13 | 2023-02-14 | Hitachi Astemo, Ltd. | Vehicular control apparatus |
EP3696025A4 (en) * | 2017-10-13 | 2021-03-17 | Hitachi Automotive Systems, Ltd. | VEHICLE CONTROL DEVICE |
CN109444232A (zh) * | 2018-12-26 | 2019-03-08 | 苏州同阳科技发展有限公司 | 一种多通道智能化污染气体监测装置与扩散溯源方法 |
CN109444232B (zh) * | 2018-12-26 | 2024-03-12 | 苏州同阳科技发展有限公司 | 一种多通道智能化污染气体监测装置与扩散溯源方法 |
CN110519266A (zh) * | 2019-08-27 | 2019-11-29 | 四川长虹电器股份有限公司 | 一种基于统计学方法的cc攻击检测的方法 |
CN110519266B (zh) * | 2019-08-27 | 2021-04-27 | 四川长虹电器股份有限公司 | 一种基于统计学方法的cc攻击检测的方法 |
CN112118141A (zh) * | 2020-09-21 | 2020-12-22 | 中山大学 | 面向通信网络的告警事件关联压缩方法及装置 |
CN112785142B (zh) * | 2021-01-19 | 2023-11-24 | 翰克偲诺水务集团有限公司 | 物联网污水处理设备预警智慧工单方法及其系统 |
CN112785142A (zh) * | 2021-01-19 | 2021-05-11 | 翰克偲诺水务集团有限公司 | 物联网污水处理设备预警智慧工单方法及其系统 |
CN113552856B (zh) * | 2021-09-22 | 2021-12-10 | 成都数之联科技有限公司 | 工艺参数根因定位方法和相关装置 |
CN113552856A (zh) * | 2021-09-22 | 2021-10-26 | 成都数之联科技有限公司 | 工艺参数根因定位方法和相关装置 |
CN117473435A (zh) * | 2023-07-21 | 2024-01-30 | 南京审计大学 | 一种基于时空特征的突发公共卫生事件虚假异常信息检测方法 |
CN117473435B (zh) * | 2023-07-21 | 2024-05-17 | 南京审计大学 | 一种基于时空特征的突发公共卫生事件虚假异常信息检测方法 |
Also Published As
Publication number | Publication date |
---|---|
CN105656693B (zh) | 2019-06-07 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
CN105656693B (zh) | 一种基于回归的信息安全异常检测的方法及系统 | |
CN105808368B (zh) | 一种基于随机概率分布的信息安全异常检测的方法及系统 | |
US11150974B2 (en) | Anomaly detection using circumstance-specific detectors | |
TWI595375B (zh) | 使用適應性行爲輪廓之異常檢測技術 | |
US9652354B2 (en) | Unsupervised anomaly detection for arbitrary time series | |
US10489711B1 (en) | Method and apparatus for predictive behavioral analytics for IT operations | |
CN105681298A (zh) | 公共信息平台中的数据安全异常监测方法及系统 | |
US11074652B2 (en) | System and method for model-based prediction using a distributed computational graph workflow | |
US20170054750A1 (en) | Risk assessment | |
CN114978568A (zh) | 使用机器学习进行数据中心管理 | |
US20150358292A1 (en) | Network security management | |
JP4112584B2 (ja) | 異常トラヒック検出方法及び装置 | |
US20190007285A1 (en) | Apparatus and Method for Defining Baseline Network Behavior and Producing Analytics and Alerts Therefrom | |
US8661113B2 (en) | Cross-cutting detection of event patterns | |
CN113518057A (zh) | 分布式拒绝服务攻击的检测方法、装置及其计算机设备 | |
CN114531338A (zh) | 一种基于调用链数据的监控告警和溯源方法及系统 | |
JP2010198579A (ja) | 異常検出システム、異常検出方法および異常検出用プログラム | |
Park et al. | Statistical process control‐based intrusion detection and monitoring | |
US20230308461A1 (en) | Event-Based Machine Learning for a Time-Series Metric | |
CN107682173B (zh) | 基于交易模型的自动故障定位方法和系统 | |
CN113259322B (zh) | 一种预防Web服务异常的方法、系统及介质 | |
Jakhale | Design of anomaly packet detection framework by data mining algorithm for network flow | |
Amiri et al. | A complete operational architecture of alert correlation | |
WO2021055964A1 (en) | System and method for crowd-sourced refinement of natural phenomenon for risk management and contract validation | |
Mata et al. | Automated detection of load changes in large-scale networks |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
C06 | Publication | ||
PB01 | Publication | ||
C10 | Entry into substantive examination | ||
SE01 | Entry into force of request for substantive examination | ||
CB02 | Change of applicant information | ||
CB02 | Change of applicant information |
Address after: 210012, Nanjing high tech Zone, Jiangsu, Nanjing Software Park, No. 99 unity Road, Eagle building, block A, 14 floor Applicant after: Nanjing Liancheng science and technology development Limited by Share Ltd Address before: A small road in Yuhuatai District of Nanjing City, Jiangsu province 210012 Building No. 158 Building 1 new ideal Applicant before: NANJING LIANCHENG TECHNOLOGY DEVELOPMENT CO., LTD. |
|
CB02 | Change of applicant information | ||
CB02 | Change of applicant information |
Address after: 210000 14F, building A, Eagle building, 99 solidarity Road, Nanjing Software Park, Nanjing hi tech Zone, Jiangsu Applicant after: Nanjing Liancheng science and technology development Limited by Share Ltd Address before: 210000, Nanjing high tech Zone, Jiangsu, Nanjing Software Park, No. 99 unity Road, Eagle building, block A, 14 floor Applicant before: Nanjing Liancheng science and technology development Limited by Share Ltd |
|
GR01 | Patent grant | ||
GR01 | Patent grant | ||
PE01 | Entry into force of the registration of the contract for pledge of patent right | ||
PE01 | Entry into force of the registration of the contract for pledge of patent right |
Denomination of invention: A method and system of information security anomaly detection based on regression Effective date of registration: 20220112 Granted publication date: 20190607 Pledgee: Bank of Hangzhou Limited by Share Ltd. Nanjing branch Pledgor: NANJING LIANCHENG TECHNOLOGY DEVELOPMENT CO.,LTD. Registration number: Y2022980000420 |