CN107395608B - 一种网络访问异常检测方法及装置 - Google Patents
一种网络访问异常检测方法及装置 Download PDFInfo
- Publication number
- CN107395608B CN107395608B CN201710656409.2A CN201710656409A CN107395608B CN 107395608 B CN107395608 B CN 107395608B CN 201710656409 A CN201710656409 A CN 201710656409A CN 107395608 B CN107395608 B CN 107395608B
- Authority
- CN
- China
- Prior art keywords
- address
- source
- information
- time
- monitored user
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Active
Links
- 238000001514 detection method Methods 0.000 title claims abstract description 37
- 238000000034 method Methods 0.000 claims abstract description 43
- 230000002159 abnormal effect Effects 0.000 claims abstract description 37
- 230000005856 abnormality Effects 0.000 claims description 17
- 238000012545 processing Methods 0.000 claims description 6
- 238000004364 calculation method Methods 0.000 claims description 2
- 230000008569 process Effects 0.000 description 8
- 230000006399 behavior Effects 0.000 description 4
- 238000010586 diagram Methods 0.000 description 4
- 238000004590 computer program Methods 0.000 description 3
- 230000006870 function Effects 0.000 description 2
- 230000006872 improvement Effects 0.000 description 2
- 230000003287 optical effect Effects 0.000 description 2
- 206010000117 Abnormal behaviour Diseases 0.000 description 1
- 238000004891 communication Methods 0.000 description 1
- 238000011161 development Methods 0.000 description 1
- 230000000694 effects Effects 0.000 description 1
- 238000005516 engineering process Methods 0.000 description 1
- 238000012986 modification Methods 0.000 description 1
- 230000004048 modification Effects 0.000 description 1
- 238000006467 substitution reaction Methods 0.000 description 1
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1408—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
- H04L63/1425—Traffic logging, e.g. anomaly detection
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
Description
Claims (12)
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201710656409.2A CN107395608B (zh) | 2017-08-03 | 2017-08-03 | 一种网络访问异常检测方法及装置 |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201710656409.2A CN107395608B (zh) | 2017-08-03 | 2017-08-03 | 一种网络访问异常检测方法及装置 |
Publications (2)
Publication Number | Publication Date |
---|---|
CN107395608A CN107395608A (zh) | 2017-11-24 |
CN107395608B true CN107395608B (zh) | 2020-09-11 |
Family
ID=60344803
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN201710656409.2A Active CN107395608B (zh) | 2017-08-03 | 2017-08-03 | 一种网络访问异常检测方法及装置 |
Country Status (1)
Country | Link |
---|---|
CN (1) | CN107395608B (zh) |
Families Citing this family (6)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN109409902A (zh) * | 2018-09-04 | 2019-03-01 | 平安普惠企业管理有限公司 | 风险用户识别方法、装置、计算机设备及存储介质 |
CN111722894B (zh) * | 2019-03-21 | 2023-04-18 | 成都鼎桥通信技术有限公司 | 应用处理方法、装置及电子设备 |
CN110417634A (zh) * | 2019-06-20 | 2019-11-05 | 平安普惠企业管理有限公司 | 基于信息安全的防刷票作弊方法及相关设备 |
CN110300123A (zh) * | 2019-07-26 | 2019-10-01 | 秒针信息技术有限公司 | 异常流量识别方法、装置、电子设备及存储介质 |
CN111199417A (zh) * | 2019-11-29 | 2020-05-26 | 北京深演智能科技股份有限公司 | 虚假设备id的识别方法及装置 |
CN115563609B (zh) * | 2022-10-10 | 2023-11-14 | 深圳掌酷软件有限公司 | 用户类型的判定方法、装置、设备及存储介质 |
Family Cites Families (5)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN103001826B (zh) * | 2012-11-29 | 2015-09-30 | 北京奇虎科技有限公司 | 用于监测用户登录的设备和方法 |
US9271135B2 (en) * | 2013-03-15 | 2016-02-23 | T-Mobile Usa, Inc. | Local network alert system for mobile devices using an IMS session and Wi-Fi access point |
CN103475637B (zh) * | 2013-04-24 | 2018-03-27 | 携程计算机技术(上海)有限公司 | 基于ip访问行为的网络访问控制方法及系统 |
CN106572057A (zh) * | 2015-10-10 | 2017-04-19 | 百度在线网络技术(北京)有限公司 | 检测用户登录异常信息的方法和装置 |
CN106506451B (zh) * | 2016-09-30 | 2019-08-27 | 百度在线网络技术(北京)有限公司 | 恶意访问的处理方法及装置 |
-
2017
- 2017-08-03 CN CN201710656409.2A patent/CN107395608B/zh active Active
Also Published As
Publication number | Publication date |
---|---|
CN107395608A (zh) | 2017-11-24 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
CN107395608B (zh) | 一种网络访问异常检测方法及装置 | |
CN108763031B (zh) | 一种基于日志的威胁情报检测方法及装置 | |
CN110677380B (zh) | 用于网络威胁指示符提取和响应的方法和相关设备 | |
CN108696473B (zh) | 攻击路径还原方法及装置 | |
US9462009B1 (en) | Detecting risky domains | |
CN107154950B (zh) | 一种日志流异常检测的方法及系统 | |
TWI595375B (zh) | 使用適應性行爲輪廓之異常檢測技術 | |
EP3506141A1 (en) | System for query injection detection using abstract syntax trees | |
CN106657057B (zh) | 反爬虫系统及方法 | |
US20180234445A1 (en) | Characterizing Behavior Anomaly Analysis Performance Based On Threat Intelligence | |
US9195842B2 (en) | Information processing method, apparatus, and system | |
CN106790041B (zh) | 一种网际协议ip信誉库生成方法及装置 | |
CN109144023A (zh) | 一种工业控制系统的安全检测方法和设备 | |
CN106790189B (zh) | 一种基于响应报文的入侵检测方法和装置 | |
CN110889597A (zh) | 业务时序指标异常检测方法及装置 | |
CN115426154A (zh) | 一种挖矿行为监测方法、装置、设备及存储介质 | |
CN106506449B (zh) | 一种未知异常的检测方法、装置及检测设备 | |
CN111756745A (zh) | 告警方法、告警装置及终端设备 | |
Sen et al. | Towards an approach to contextual detection of multi-stage cyber attacks in smart grids | |
CN114866296A (zh) | 入侵检测方法、装置、设备及可读存储介质 | |
CN114157480A (zh) | 网络攻击方案的确定方法、装置、设备和存储介质 | |
CN114461864A (zh) | 一种告警溯源方法和装置 | |
CN115955333A (zh) | C2服务器识别方法、装置、电子设备及可读存储介质 | |
CN110830518B (zh) | 溯源分析方法、装置、电子设备及存储介质 | |
US11677582B2 (en) | Detecting anomalies on a controller area network bus |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
PB01 | Publication | ||
PB01 | Publication | ||
SE01 | Entry into force of request for substantive examination | ||
SE01 | Entry into force of request for substantive examination | ||
TA01 | Transfer of patent application right |
Effective date of registration: 20190402 Address after: 100015 15, 17 floor 1701-26, 3 building, 10 Jiuxianqiao Road, Chaoyang District, Beijing. Applicant after: BEIJING QIANXIN TECHNOLOGY Co.,Ltd. Applicant after: LEGENDSEC INFORMATION TECHNOLOGY (BEIJING) Inc. Address before: 100015 15, 17 floor 1701-26, 3 building, 10 Jiuxianqiao Road, Chaoyang District, Beijing. Applicant before: BEIJING QIANXIN TECHNOLOGY Co.,Ltd. |
|
TA01 | Transfer of patent application right | ||
CB02 | Change of applicant information |
Address after: 100088 Building 3 332, 102, 28 Xinjiekouwai Street, Xicheng District, Beijing Applicant after: QAX Technology Group Inc. Applicant after: LEGENDSEC INFORMATION TECHNOLOGY (BEIJING) Inc. Address before: 100015 Jiuxianqiao Chaoyang District Beijing Road No. 10, building 15, floor 17, layer 1701-26, 3 Applicant before: BEIJING QIANXIN TECHNOLOGY Co.,Ltd. Applicant before: LEGENDSEC INFORMATION TECHNOLOGY (BEIJING) Inc. |
|
CB02 | Change of applicant information | ||
GR01 | Patent grant | ||
GR01 | Patent grant | ||
CP01 | Change in the name or title of a patent holder |
Address after: Room 332, 3 / F, Building 102, 28 xinjiekouwei street, Xicheng District, Beijing 100088 Patentee after: QAX Technology Group Inc. Patentee after: Qianxin Wangshen information technology (Beijing) Co.,Ltd. Address before: Room 332, 3 / F, Building 102, 28 xinjiekouwei street, Xicheng District, Beijing 100088 Patentee before: QAX Technology Group Inc. Patentee before: LEGENDSEC INFORMATION TECHNOLOGY (BEIJING) Inc. |
|
CP01 | Change in the name or title of a patent holder |