CN106685964B - 基于恶意网络流量词库的恶意软件检测方法及系统 - Google Patents
基于恶意网络流量词库的恶意软件检测方法及系统 Download PDFInfo
- Publication number
- CN106685964B CN106685964B CN201611243439.2A CN201611243439A CN106685964B CN 106685964 B CN106685964 B CN 106685964B CN 201611243439 A CN201611243439 A CN 201611243439A CN 106685964 B CN106685964 B CN 106685964B
- Authority
- CN
- China
- Prior art keywords
- word
- malicious
- word set
- normal
- network traffic
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Active
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1408—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
- H04L63/1425—Traffic logging, e.g. anomaly detection
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/55—Detecting local intrusion or implementing counter-measures
- G06F21/56—Computer malware detection or handling, e.g. anti-virus arrangements
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1441—Countermeasures against malicious traffic
- H04L63/145—Countermeasures against malicious traffic the attack involving the propagation of malware through the network, e.g. viruses, trojans or worms
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- General Engineering & Computer Science (AREA)
- Computer Hardware Design (AREA)
- General Health & Medical Sciences (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Health & Medical Sciences (AREA)
- Computing Systems (AREA)
- Virology (AREA)
- Software Systems (AREA)
- Theoretical Computer Science (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Computer And Data Communications (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
Description
Claims (5)
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201611243439.2A CN106685964B (zh) | 2016-12-29 | 2016-12-29 | 基于恶意网络流量词库的恶意软件检测方法及系统 |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201611243439.2A CN106685964B (zh) | 2016-12-29 | 2016-12-29 | 基于恶意网络流量词库的恶意软件检测方法及系统 |
Publications (2)
Publication Number | Publication Date |
---|---|
CN106685964A CN106685964A (zh) | 2017-05-17 |
CN106685964B true CN106685964B (zh) | 2020-10-30 |
Family
ID=58873260
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN201611243439.2A Active CN106685964B (zh) | 2016-12-29 | 2016-12-29 | 基于恶意网络流量词库的恶意软件检测方法及系统 |
Country Status (1)
Country | Link |
---|---|
CN (1) | CN106685964B (zh) |
Families Citing this family (7)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN108470027A (zh) * | 2018-03-30 | 2018-08-31 | 广州优视网络科技有限公司 | 色情应用识别方法和装置、计算设备和存储介质 |
CN108540471B (zh) * | 2018-04-08 | 2020-10-02 | 南京邮电大学 | 移动应用网络流量聚类方法、计算机可读存储介质和终端 |
CN109117634B (zh) * | 2018-09-05 | 2020-10-23 | 济南大学 | 基于网络流量多视图融合的恶意软件检测方法及系统 |
CN111062034A (zh) * | 2018-10-16 | 2020-04-24 | 中移(杭州)信息技术有限公司 | 一种Webshell文件检测方法、装置、电子设备及存储介质 |
CN111368289B (zh) * | 2018-12-26 | 2023-08-29 | 中兴通讯股份有限公司 | 一种恶意软件检测方法和装置 |
CN111651761B (zh) * | 2019-03-04 | 2023-04-14 | 腾讯科技(深圳)有限公司 | 一种黑产电子设备检测方法、装置、服务器及存储介质 |
CN113705619B (zh) * | 2021-08-03 | 2023-09-12 | 广州大学 | 一种恶意流量检测方法、系统、计算机及介质 |
Citations (5)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN102779249A (zh) * | 2012-06-28 | 2012-11-14 | 奇智软件(北京)有限公司 | 恶意程序检测方法及扫描引擎 |
CN102821002A (zh) * | 2011-06-09 | 2012-12-12 | 中国移动通信集团河南有限公司信阳分公司 | 网络流量异常检测方法和系统 |
CN103473506A (zh) * | 2013-08-30 | 2013-12-25 | 北京奇虎科技有限公司 | 用于识别恶意apk文件的方法和装置 |
CN104598813A (zh) * | 2014-12-09 | 2015-05-06 | 西安电子科技大学 | 一种基于集成学习和半监督svm的计算机入侵检测方法 |
CN105007282A (zh) * | 2015-08-10 | 2015-10-28 | 济南大学 | 面向网络服务提供商的恶意软件网络行为检测方法及系统 |
Family Cites Families (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US9038178B1 (en) * | 2012-06-25 | 2015-05-19 | Emc Corporation | Detection of malware beaconing activities |
-
2016
- 2016-12-29 CN CN201611243439.2A patent/CN106685964B/zh active Active
Patent Citations (5)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN102821002A (zh) * | 2011-06-09 | 2012-12-12 | 中国移动通信集团河南有限公司信阳分公司 | 网络流量异常检测方法和系统 |
CN102779249A (zh) * | 2012-06-28 | 2012-11-14 | 奇智软件(北京)有限公司 | 恶意程序检测方法及扫描引擎 |
CN103473506A (zh) * | 2013-08-30 | 2013-12-25 | 北京奇虎科技有限公司 | 用于识别恶意apk文件的方法和装置 |
CN104598813A (zh) * | 2014-12-09 | 2015-05-06 | 西安电子科技大学 | 一种基于集成学习和半监督svm的计算机入侵检测方法 |
CN105007282A (zh) * | 2015-08-10 | 2015-10-28 | 济南大学 | 面向网络服务提供商的恶意软件网络行为检测方法及系统 |
Also Published As
Publication number | Publication date |
---|---|
CN106685964A (zh) | 2017-05-17 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
CN106685964B (zh) | 基于恶意网络流量词库的恶意软件检测方法及系统 | |
CN106709345B (zh) | 基于深度学习方法推断恶意代码规则的方法、系统及设备 | |
CN109753800B (zh) | 融合频繁项集与随机森林算法的Android恶意应用检测方法及系统 | |
WO2020108063A1 (zh) | 特征词的确定方法、装置和服务器 | |
CN103336766A (zh) | 短文本垃圾识别以及建模方法和装置 | |
CN109871686A (zh) | 基于图标表示和软件行为一致性分析的恶意程序识别方法及装置 | |
CN103324745A (zh) | 基于贝叶斯模型的文本垃圾识别方法和系统 | |
CN111259397B (zh) | 一种基于马尔科夫图和深度学习的恶意软件分类方法 | |
CN112507704A (zh) | 多意图识别方法、装置、设备及存储介质 | |
CN110019653B (zh) | 一种融合文本和标签网络的社交内容表征方法和系统 | |
CN111260220A (zh) | 群控设备识别方法、装置、电子设备和存储介质 | |
CN110287311A (zh) | 文本分类方法及装置、存储介质、计算机设备 | |
CN112667750A (zh) | 一种报文类别的确定、识别方法及装置 | |
CN112800919A (zh) | 一种检测目标类型视频方法、装置、设备以及存储介质 | |
CN109391620A (zh) | 异常行为判定模型的建立方法、系统、服务器及存储介质 | |
CN115632874A (zh) | 一种实体对象的威胁检测方法、装置、设备及存储介质 | |
CN114490998A (zh) | 文本信息的抽取方法、装置、电子设备和存储介质 | |
CN114553591A (zh) | 随机森林模型的训练方法、异常流量检测方法及装置 | |
Yujie et al. | End-to-end android malware classification based on pure traffic images | |
CN114373212A (zh) | 人脸识别模型构建方法、人脸识别方法及相关设备 | |
CN114444514B (zh) | 语义匹配模型训练、语义匹配方法及相关装置 | |
CN106685963B (zh) | 一种恶意网络流量词库的建立方法及建立系统 | |
CN115906797A (zh) | 文本实体对齐方法、装置、设备及介质 | |
CN114818736A (zh) | 文本处理方法、用于短文本的链指方法、装置及存储介质 | |
CN114756578A (zh) | Sql执行计划的确定方法和装置 |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
PB01 | Publication | ||
PB01 | Publication | ||
SE01 | Entry into force of request for substantive examination | ||
SE01 | Entry into force of request for substantive examination | ||
CB03 | Change of inventor or designer information |
Inventor after: Chen Zhenxiang Inventor after: Wang Shanshan Inventor after: Sun Runyuan Inventor after: Yang Bo Inventor after: Peng Lizhi Inventor after: Liu Kun Inventor before: Wang Shanshan Inventor before: Chen Zhenxiang Inventor before: Sun Runyuan Inventor before: Yang Bo Inventor before: Peng Lizhi Inventor before: Liu Kun |
|
CB03 | Change of inventor or designer information | ||
GR01 | Patent grant | ||
GR01 | Patent grant |