CN108683687A - 一种网络攻击识别方法及系统 - Google Patents
一种网络攻击识别方法及系统 Download PDFInfo
- Publication number
- CN108683687A CN108683687A CN201810713042.8A CN201810713042A CN108683687A CN 108683687 A CN108683687 A CN 108683687A CN 201810713042 A CN201810713042 A CN 201810713042A CN 108683687 A CN108683687 A CN 108683687A
- Authority
- CN
- China
- Prior art keywords
- attack
- network
- data
- feature
- response
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Granted
Links
- 238000000034 method Methods 0.000 title claims abstract description 69
- 230000004044 response Effects 0.000 claims abstract description 277
- 238000012549 training Methods 0.000 claims description 65
- 238000000605 extraction Methods 0.000 claims description 62
- 238000013473 artificial intelligence Methods 0.000 claims description 43
- 238000001514 detection method Methods 0.000 claims description 23
- 238000004590 computer program Methods 0.000 claims description 11
- 238000004422 calculation algorithm Methods 0.000 claims description 9
- 238000004364 calculation method Methods 0.000 claims description 4
- 230000008676 import Effects 0.000 claims description 4
- 238000002347 injection Methods 0.000 description 20
- 239000007924 injection Substances 0.000 description 20
- 239000000284 extract Substances 0.000 description 14
- 230000006870 function Effects 0.000 description 14
- 238000010586 diagram Methods 0.000 description 12
- 230000009545 invasion Effects 0.000 description 8
- 230000014509 gene expression Effects 0.000 description 6
- 238000012163 sequencing technique Methods 0.000 description 6
- 238000012546 transfer Methods 0.000 description 6
- 241001269238 Data Species 0.000 description 5
- 230000009471 action Effects 0.000 description 4
- 230000008595 infiltration Effects 0.000 description 4
- 238000001764 infiltration Methods 0.000 description 4
- 238000012545 processing Methods 0.000 description 4
- 239000000243 solution Substances 0.000 description 4
- 230000008901 benefit Effects 0.000 description 3
- 238000005516 engineering process Methods 0.000 description 3
- 230000008569 process Effects 0.000 description 3
- 230000006399 behavior Effects 0.000 description 2
- 230000003542 behavioural effect Effects 0.000 description 2
- 238000012512 characterization method Methods 0.000 description 2
- 238000013145 classification model Methods 0.000 description 2
- 238000004140 cleaning Methods 0.000 description 2
- 238000013135 deep learning Methods 0.000 description 2
- 230000000694 effects Effects 0.000 description 2
- 230000000977 initiatory effect Effects 0.000 description 2
- 238000011835 investigation Methods 0.000 description 2
- 230000003044 adaptive effect Effects 0.000 description 1
- 238000004458 analytical method Methods 0.000 description 1
- 230000002155 anti-virotic effect Effects 0.000 description 1
- 230000000739 chaotic effect Effects 0.000 description 1
- 238000007635 classification algorithm Methods 0.000 description 1
- 230000006378 damage Effects 0.000 description 1
- 238000007405 data analysis Methods 0.000 description 1
- 238000003066 decision tree Methods 0.000 description 1
- 230000007547 defect Effects 0.000 description 1
- 238000011161 development Methods 0.000 description 1
- 230000004069 differentiation Effects 0.000 description 1
- 238000011156 evaluation Methods 0.000 description 1
- 230000006872 improvement Effects 0.000 description 1
- 238000010801 machine learning Methods 0.000 description 1
- 230000004048 modification Effects 0.000 description 1
- 238000012986 modification Methods 0.000 description 1
- 238000012544 monitoring process Methods 0.000 description 1
- 230000035772 mutation Effects 0.000 description 1
- 230000008520 organization Effects 0.000 description 1
- 238000006467 substitution reaction Methods 0.000 description 1
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1408—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
- H04L63/1416—Event detection, e.g. attack signature detection
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L41/00—Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
- H04L41/06—Management of faults, events, alarms or notifications
- H04L41/0631—Management of faults, events, alarms or notifications using root cause analysis; using analysis of correlation between notifications, alarms or events based on decision criteria, e.g. hierarchy, tree or time analysis
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1408—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
- H04L63/1425—Traffic logging, e.g. anomaly detection
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1433—Vulnerability analysis
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
- Computer And Data Communications (AREA)
Abstract
Description
Claims (10)
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201810713042.8A CN108683687B (zh) | 2018-06-29 | 2018-06-29 | 一种网络攻击识别方法及系统 |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201810713042.8A CN108683687B (zh) | 2018-06-29 | 2018-06-29 | 一种网络攻击识别方法及系统 |
Publications (2)
Publication Number | Publication Date |
---|---|
CN108683687A true CN108683687A (zh) | 2018-10-19 |
CN108683687B CN108683687B (zh) | 2021-08-10 |
Family
ID=63813103
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN201810713042.8A Active CN108683687B (zh) | 2018-06-29 | 2018-06-29 | 一种网络攻击识别方法及系统 |
Country Status (1)
Country | Link |
---|---|
CN (1) | CN108683687B (zh) |
Cited By (14)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN111181759A (zh) * | 2019-08-08 | 2020-05-19 | 腾讯科技(深圳)有限公司 | 一种网络设备的异常识别方法、装置、设备及存储介质 |
CN111262730A (zh) * | 2020-01-10 | 2020-06-09 | 中国银联股份有限公司 | 一种告警信息的处理方法及装置 |
CN111385270A (zh) * | 2018-12-29 | 2020-07-07 | 北京奇虎科技有限公司 | 基于waf的网络攻击检测方法及装置 |
CN111385271A (zh) * | 2018-12-29 | 2020-07-07 | 北京奇虎科技有限公司 | 网络攻击的检测方法、装置及系统 |
CN111510434A (zh) * | 2020-03-24 | 2020-08-07 | 中国建设银行股份有限公司 | 网络入侵检测方法、系统及相关设备 |
CN112543168A (zh) * | 2019-09-20 | 2021-03-23 | 中移(苏州)软件技术有限公司 | 网络攻击的检测方法、装置、服务器及存储介质 |
CN113162891A (zh) * | 2020-01-23 | 2021-07-23 | 北京华顺信安科技有限公司 | 攻击流量快速识别系统、方法、计算机可读介质及设备 |
CN113472772A (zh) * | 2021-06-29 | 2021-10-01 | 深信服科技股份有限公司 | 网络攻击的检测方法、装置、电子设备及存储介质 |
CN113765859A (zh) * | 2020-06-05 | 2021-12-07 | 北京神州泰岳软件股份有限公司 | 网络安全过滤方法及装置 |
CN114338202A (zh) * | 2021-12-30 | 2022-04-12 | 奇安信科技集团股份有限公司 | 网络攻击结果的检测方法、装置、计算设备及存储介质 |
CN115174201A (zh) * | 2022-06-30 | 2022-10-11 | 北京安博通科技股份有限公司 | 一种基于筛选标签的安全规则管理方法及装置 |
CN115643119A (zh) * | 2022-12-26 | 2023-01-24 | 北京微步在线科技有限公司 | 一种网络攻击检测方法及装置 |
CN116723055A (zh) * | 2023-08-08 | 2023-09-08 | 中国电信股份有限公司 | 漏洞检测方法、装置、存储介质和电子设备 |
CN117675415A (zh) * | 2024-01-31 | 2024-03-08 | 北京六方云信息技术有限公司 | 攻击防御方法、装置、终端设备以及存储介质 |
Citations (10)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN101902334A (zh) * | 2009-05-25 | 2010-12-01 | 北京启明星辰信息技术股份有限公司 | 一种安全事件实时确认方法及系统 |
CN105100122A (zh) * | 2015-09-08 | 2015-11-25 | 南京联成科技发展有限公司 | 一种基于大数据分析的威胁检测和预警的方法及系统 |
CN105337792A (zh) * | 2015-08-25 | 2016-02-17 | 王子瑜 | 网络攻击有效性的检测方法及系统 |
CN107046518A (zh) * | 2016-02-05 | 2017-08-15 | 阿里巴巴集团控股有限公司 | 网络攻击的检测方法及装置 |
US20170289186A1 (en) * | 2016-03-31 | 2017-10-05 | Stuart Staniford | System and method to protect a webserver against application exploits and attacks |
CN107454037A (zh) * | 2016-05-30 | 2017-12-08 | 深圳市深信服电子科技有限公司 | 网络攻击的识别方法和系统 |
CN107483458A (zh) * | 2017-08-29 | 2017-12-15 | 杭州迪普科技股份有限公司 | 网络攻击的识别方法及装置、计算机可读存储介质 |
CN107577945A (zh) * | 2017-09-28 | 2018-01-12 | 阿里巴巴集团控股有限公司 | Url攻击检测方法、装置以及电子设备 |
CN107659583A (zh) * | 2017-10-27 | 2018-02-02 | 深信服科技股份有限公司 | 一种检测事中攻击的方法及系统 |
EP3337129A1 (en) * | 2016-12-19 | 2018-06-20 | Verisign, Inc. | Dynamic allocation of a signal receiver for dissemination of threat information |
-
2018
- 2018-06-29 CN CN201810713042.8A patent/CN108683687B/zh active Active
Patent Citations (10)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN101902334A (zh) * | 2009-05-25 | 2010-12-01 | 北京启明星辰信息技术股份有限公司 | 一种安全事件实时确认方法及系统 |
CN105337792A (zh) * | 2015-08-25 | 2016-02-17 | 王子瑜 | 网络攻击有效性的检测方法及系统 |
CN105100122A (zh) * | 2015-09-08 | 2015-11-25 | 南京联成科技发展有限公司 | 一种基于大数据分析的威胁检测和预警的方法及系统 |
CN107046518A (zh) * | 2016-02-05 | 2017-08-15 | 阿里巴巴集团控股有限公司 | 网络攻击的检测方法及装置 |
US20170289186A1 (en) * | 2016-03-31 | 2017-10-05 | Stuart Staniford | System and method to protect a webserver against application exploits and attacks |
CN107454037A (zh) * | 2016-05-30 | 2017-12-08 | 深圳市深信服电子科技有限公司 | 网络攻击的识别方法和系统 |
EP3337129A1 (en) * | 2016-12-19 | 2018-06-20 | Verisign, Inc. | Dynamic allocation of a signal receiver for dissemination of threat information |
CN107483458A (zh) * | 2017-08-29 | 2017-12-15 | 杭州迪普科技股份有限公司 | 网络攻击的识别方法及装置、计算机可读存储介质 |
CN107577945A (zh) * | 2017-09-28 | 2018-01-12 | 阿里巴巴集团控股有限公司 | Url攻击检测方法、装置以及电子设备 |
CN107659583A (zh) * | 2017-10-27 | 2018-02-02 | 深信服科技股份有限公司 | 一种检测事中攻击的方法及系统 |
Non-Patent Citations (1)
Title |
---|
刘志杰等: "一个基于复合攻击路径图的报警关联算法", 《南京大学学报》 * |
Cited By (20)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN111385270A (zh) * | 2018-12-29 | 2020-07-07 | 北京奇虎科技有限公司 | 基于waf的网络攻击检测方法及装置 |
CN111385271A (zh) * | 2018-12-29 | 2020-07-07 | 北京奇虎科技有限公司 | 网络攻击的检测方法、装置及系统 |
CN111181759A (zh) * | 2019-08-08 | 2020-05-19 | 腾讯科技(深圳)有限公司 | 一种网络设备的异常识别方法、装置、设备及存储介质 |
CN112543168A (zh) * | 2019-09-20 | 2021-03-23 | 中移(苏州)软件技术有限公司 | 网络攻击的检测方法、装置、服务器及存储介质 |
CN111262730B (zh) * | 2020-01-10 | 2022-08-30 | 中国银联股份有限公司 | 一种告警信息的处理方法及装置 |
CN111262730A (zh) * | 2020-01-10 | 2020-06-09 | 中国银联股份有限公司 | 一种告警信息的处理方法及装置 |
CN113162891A (zh) * | 2020-01-23 | 2021-07-23 | 北京华顺信安科技有限公司 | 攻击流量快速识别系统、方法、计算机可读介质及设备 |
CN113162891B (zh) * | 2020-01-23 | 2024-03-26 | 北京华顺信安科技有限公司 | 攻击流量快速识别系统、方法、计算机可读介质及设备 |
CN111510434A (zh) * | 2020-03-24 | 2020-08-07 | 中国建设银行股份有限公司 | 网络入侵检测方法、系统及相关设备 |
CN113765859B (zh) * | 2020-06-05 | 2023-12-26 | 北京神州泰岳软件股份有限公司 | 网络安全过滤方法及装置 |
CN113765859A (zh) * | 2020-06-05 | 2021-12-07 | 北京神州泰岳软件股份有限公司 | 网络安全过滤方法及装置 |
CN113472772A (zh) * | 2021-06-29 | 2021-10-01 | 深信服科技股份有限公司 | 网络攻击的检测方法、装置、电子设备及存储介质 |
CN114338202A (zh) * | 2021-12-30 | 2022-04-12 | 奇安信科技集团股份有限公司 | 网络攻击结果的检测方法、装置、计算设备及存储介质 |
CN114338202B (zh) * | 2021-12-30 | 2024-10-01 | 奇安信科技集团股份有限公司 | 网络攻击结果的检测方法、装置、计算设备及存储介质 |
CN115174201A (zh) * | 2022-06-30 | 2022-10-11 | 北京安博通科技股份有限公司 | 一种基于筛选标签的安全规则管理方法及装置 |
CN115174201B (zh) * | 2022-06-30 | 2023-08-01 | 北京安博通科技股份有限公司 | 一种基于筛选标签的安全规则管理方法及装置 |
CN115643119A (zh) * | 2022-12-26 | 2023-01-24 | 北京微步在线科技有限公司 | 一种网络攻击检测方法及装置 |
CN116723055A (zh) * | 2023-08-08 | 2023-09-08 | 中国电信股份有限公司 | 漏洞检测方法、装置、存储介质和电子设备 |
CN117675415A (zh) * | 2024-01-31 | 2024-03-08 | 北京六方云信息技术有限公司 | 攻击防御方法、装置、终端设备以及存储介质 |
CN117675415B (zh) * | 2024-01-31 | 2024-04-19 | 北京六方云信息技术有限公司 | 攻击防御方法、装置、终端设备以及存储介质 |
Also Published As
Publication number | Publication date |
---|---|
CN108683687B (zh) | 2021-08-10 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
CN108683687A (zh) | 一种网络攻击识别方法及系统 | |
CN108471429A (zh) | 一种网络攻击告警方法及系统 | |
CN108881265A (zh) | 一种基于人工智能的网络攻击检测方法及系统 | |
CN108881263A (zh) | 一种网络攻击结果检测方法及系统 | |
CN108833186A (zh) | 一种网络攻击预测方法及装置 | |
CN108667854A (zh) | 网络漏洞检测方法及装置、网络漏洞自动发布系统 | |
CN108833185B (zh) | 一种网络攻击路线还原方法及系统 | |
CN106549974B (zh) | 预测社交网络账户是否恶意的设备、方法及系统 | |
Ektefa et al. | Intrusion detection using data mining techniques | |
CN109600362B (zh) | 基于识别模型的僵尸主机识别方法、识别设备及介质 | |
CN110460611B (zh) | 基于机器学习的全流量攻击检测技术 | |
KR101692982B1 (ko) | 로그 분석 및 특징 자동 학습을 통한 위험 감지 및 접근제어 자동화 시스템 | |
CN104598820A (zh) | 一种基于特征行为分析的木马病检测方法 | |
CN115001934A (zh) | 一种工控安全风险分析系统及方法 | |
CN113709170A (zh) | 资产安全运营系统、方法和装置 | |
CN110365625B (zh) | 物联网安全检测方法、装置及存储介质 | |
US20230396640A1 (en) | Security event management system and associated method | |
Agrawal et al. | A SURVEY ON ATTACKS AND APPROACHES OF INTRUSION DETECTION SYSTEMS. | |
CN112084239A (zh) | 基于大数据特征模型识别的信令网络安全挖掘分析方法 | |
CN115442159B (zh) | 一种基于家用路由的风险管控方法、系统和存储介质 | |
CN114124453B (zh) | 网络安全信息的处理方法、装置、电子设备及储存介质 | |
CN116980159A (zh) | 异常行为检测方法、装置、电子设备及存储介质 | |
CN115603995A (zh) | 一种信息处理方法、装置、设备及计算机可读存储介质 | |
CN115664931A (zh) | 一种告警数据的关联方法、装置、存储介质及设备 | |
Mohamed et al. | Machine Learning-Based Intrusion Detection Systems for Enhancing Cybersecurity |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
PB01 | Publication | ||
PB01 | Publication | ||
SE01 | Entry into force of request for substantive examination | ||
SE01 | Entry into force of request for substantive examination | ||
GR01 | Patent grant | ||
GR01 | Patent grant | ||
TR01 | Transfer of patent right |
Effective date of registration: 20220810 Address after: 300450 No. 9-3-401, No. 39, Gaoxin 6th Road, Binhai Science Park, Binhai New Area, Tianjin Patentee after: 3600 Technology Group Co.,Ltd. Address before: 100088 room 112, block D, 28 new street, new street, Xicheng District, Beijing (Desheng Park) Patentee before: BEIJING QIHOO TECHNOLOGY Co.,Ltd. |
|
TR01 | Transfer of patent right | ||
TR01 | Transfer of patent right |
Effective date of registration: 20230717 Address after: 1765, floor 17, floor 15, building 3, No. 10 Jiuxianqiao Road, Chaoyang District, Beijing 100015 Patentee after: Beijing Hongxiang Technical Service Co.,Ltd. Address before: 300450 No. 9-3-401, No. 39, Gaoxin 6th Road, Binhai Science Park, Binhai New Area, Tianjin Patentee before: 3600 Technology Group Co.,Ltd. |
|
TR01 | Transfer of patent right | ||
CP03 | Change of name, title or address |
Address after: 1765, floor 17, floor 15, building 3, No. 10 Jiuxianqiao Road, Chaoyang District, Beijing 100015 Patentee after: Beijing 360 Zhiling Technology Co.,Ltd. Country or region after: China Address before: 1765, floor 17, floor 15, building 3, No. 10 Jiuxianqiao Road, Chaoyang District, Beijing 100015 Patentee before: Beijing Hongxiang Technical Service Co.,Ltd. Country or region before: China |