CN106561024B - 一种基于企业级的远程apt检测方法及高性能服务器 - Google Patents
一种基于企业级的远程apt检测方法及高性能服务器 Download PDFInfo
- Publication number
- CN106561024B CN106561024B CN201510998978.6A CN201510998978A CN106561024B CN 106561024 B CN106561024 B CN 106561024B CN 201510998978 A CN201510998978 A CN 201510998978A CN 106561024 B CN106561024 B CN 106561024B
- Authority
- CN
- China
- Prior art keywords
- enterprise
- data
- performance server
- detected
- server
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Active
Links
- 238000001514 detection method Methods 0.000 title claims abstract description 53
- 238000000034 method Methods 0.000 claims description 18
- 238000004458 analytical method Methods 0.000 claims description 15
- 230000001360 synchronised effect Effects 0.000 claims description 13
- 230000008569 process Effects 0.000 claims description 5
- 230000002155 anti-virotic effect Effects 0.000 abstract description 3
- 230000006399 behavior Effects 0.000 description 10
- 230000008859 change Effects 0.000 description 6
- 230000007774 longterm Effects 0.000 description 2
- 230000002085 persistent effect Effects 0.000 description 2
- 238000012300 Sequence Analysis Methods 0.000 description 1
- 230000002159 abnormal effect Effects 0.000 description 1
- 230000009286 beneficial effect Effects 0.000 description 1
- 238000010586 diagram Methods 0.000 description 1
- 208000015181 infectious disease Diseases 0.000 description 1
- 230000007246 mechanism Effects 0.000 description 1
- 230000004048 modification Effects 0.000 description 1
- 238000012986 modification Methods 0.000 description 1
- 230000002265 prevention Effects 0.000 description 1
- 230000000750 progressive effect Effects 0.000 description 1
- 230000026676 system process Effects 0.000 description 1
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1441—Countermeasures against malicious traffic
- H04L63/1466—Active attacks involving interception, injection, modification, spoofing of data unit addresses, e.g. hijacking, packet injection or TCP sequence number attacks
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1408—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
- H04L63/1416—Event detection, e.g. attack signature detection
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1441—Countermeasures against malicious traffic
- H04L63/1475—Passive attacks, e.g. eavesdropping or listening without modification of the traffic monitored
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L67/00—Network arrangements or protocols for supporting network services or applications
- H04L67/01—Protocols
- H04L67/02—Protocols based on web technology, e.g. hypertext transfer protocol [HTTP]
- H04L67/025—Protocols based on web technology, e.g. hypertext transfer protocol [HTTP] for remote control or remote monitoring of applications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L67/00—Network arrangements or protocols for supporting network services or applications
- H04L67/01—Protocols
- H04L67/06—Protocols specially adapted for file transfer, e.g. file transfer protocol [FTP]
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Computer And Data Communications (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
Description
Claims (8)
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201510998978.6A CN106561024B (zh) | 2015-12-28 | 2015-12-28 | 一种基于企业级的远程apt检测方法及高性能服务器 |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201510998978.6A CN106561024B (zh) | 2015-12-28 | 2015-12-28 | 一种基于企业级的远程apt检测方法及高性能服务器 |
Publications (2)
| Publication Number | Publication Date |
|---|---|
| CN106561024A CN106561024A (zh) | 2017-04-12 |
| CN106561024B true CN106561024B (zh) | 2020-05-19 |
Family
ID=58485464
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| CN201510998978.6A Active CN106561024B (zh) | 2015-12-28 | 2015-12-28 | 一种基于企业级的远程apt检测方法及高性能服务器 |
Country Status (1)
| Country | Link |
|---|---|
| CN (1) | CN106561024B (zh) |
Family Cites Families (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN101707632A (zh) * | 2009-10-28 | 2010-05-12 | 浪潮电子信息产业股份有限公司 | 一种动态监控服务器集群性能并实时报警的方法 |
| US8677487B2 (en) * | 2011-10-18 | 2014-03-18 | Mcafee, Inc. | System and method for detecting a malicious command and control channel |
| CN103532780B (zh) * | 2013-10-11 | 2017-09-22 | 北京有度致远信息科技股份有限公司 | 用于it领域的运维监控一体化系统及一体化监控方法 |
| CN103634306B (zh) * | 2013-11-18 | 2017-09-15 | 北京奇虎科技有限公司 | 网络数据的安全检测方法和安全检测服务器 |
-
2015
- 2015-12-28 CN CN201510998978.6A patent/CN106561024B/zh active Active
Also Published As
| Publication number | Publication date |
|---|---|
| CN106561024A (zh) | 2017-04-12 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| EP3225009B1 (en) | Systems and methods for malicious code detection | |
| KR101057432B1 (ko) | 프로세스의 행위 분석을 통한 유해 프로그램을 실시간으로 탐지하고 차단하는 시스템, 방법, 프로그램 및 기록매체 | |
| US10095866B2 (en) | System and method for threat risk scoring of security threats | |
| CN107659583B (zh) | 一种检测事中攻击的方法及系统 | |
| US8793682B2 (en) | Methods, systems, and computer program products for controlling software application installations | |
| RU2726032C2 (ru) | Системы и способы обнаружения вредоносных программ с алгоритмом генерации доменов (dga) | |
| KR101697189B1 (ko) | 시나리오 기반 사이버 공격 이력 추적 시스템 및 방법 | |
| HK1244125A1 (zh) | 用於惡意代碼檢測的準確保證的系統及方法 | |
| EP3374870B1 (en) | Threat risk scoring of security threats | |
| US9961093B1 (en) | Monitoring for reverse-connection network activity to detect a remote-administration tool | |
| CN111565202B (zh) | 一种内网漏洞攻击防御方法及相关装置 | |
| Zhang et al. | Anteater: Advanced persistent threat detection with program network traffic behavior | |
| US20050086512A1 (en) | Worm blocking system and method using hardware-based pattern matching | |
| KR20110131627A (ko) | 악성 코드 진단 및 복구 장치, 그리고 이를 위한 단말 장치 | |
| KR102211846B1 (ko) | 랜섬웨어 탐지 시스템 및 그의 동작 방법 | |
| Kurniawan et al. | File integrity monitoring as a method for detecting and preventing web defacement attacks | |
| CN106561024B (zh) | 一种基于企业级的远程apt检测方法及高性能服务器 | |
| EP3252645B1 (en) | System and method of detecting malicious computer systems | |
| CN115442128A (zh) | 网络入侵检测方法及装置 | |
| Kono et al. | An unknown malware detection using execution registry access | |
| CN114969739A (zh) | 一种基于时间线的网络攻击溯源分析方法及系统 | |
| CN115720150A (zh) | 基于rasp的waf联动防护方法、装置、设备及介质 | |
| KR101283440B1 (ko) | 부비트랩 시그너처를 이용한 정보유출 차단시스템 및 그 방법 | |
| CN117439757A (zh) | 终端风险程序的数据处理方法、装置和服务器 | |
| HK40027433A (zh) | 一种内网漏洞攻击防御方法及相关装置 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| PB01 | Publication | ||
| PB01 | Publication | ||
| SE01 | Entry into force of request for substantive examination | ||
| SE01 | Entry into force of request for substantive examination | ||
| CB02 | Change of applicant information | ||
| CB02 | Change of applicant information |
Address after: 150028 Building 7, Innovation Plaza, Science and Technology Innovation City, Harbin High-tech Industrial Development Zone, Heilongjiang Province (838 Shikun Road) Applicant after: Harbin antiy Technology Group Limited by Share Ltd Address before: 506 room 162, Hongqi Avenue, Nangang District, Harbin Development Zone, Heilongjiang, 150090 Applicant before: Harbin Antiy Technology Co., Ltd. |
|
| GR01 | Patent grant | ||
| GR01 | Patent grant | ||
| CP01 | Change in the name or title of a patent holder | ||
| CP01 | Change in the name or title of a patent holder |
Address after: 150028 Building 7, Innovation Plaza, Science and Technology Innovation City, Harbin High-tech Industrial Development Zone, Heilongjiang Province (838 Shikun Road) Patentee after: Antan Technology Group Co.,Ltd. Address before: 150028 Building 7, Innovation Plaza, Science and Technology Innovation City, Harbin High-tech Industrial Development Zone, Heilongjiang Province (838 Shikun Road) Patentee before: Harbin Antian Science and Technology Group Co.,Ltd. |