CN109325193A - 基于机器学习的waf正常流量建模方法以及装置 - Google Patents
基于机器学习的waf正常流量建模方法以及装置 Download PDFInfo
- Publication number
- CN109325193A CN109325193A CN201811206594.6A CN201811206594A CN109325193A CN 109325193 A CN109325193 A CN 109325193A CN 201811206594 A CN201811206594 A CN 201811206594A CN 109325193 A CN109325193 A CN 109325193A
- Authority
- CN
- China
- Prior art keywords
- url
- target
- waf
- probability
- character
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Granted
Links
- 238000000034 method Methods 0.000 title claims abstract description 66
- 238000010801 machine learning Methods 0.000 title claims abstract description 47
- 230000002159 abnormal effect Effects 0.000 claims abstract description 30
- 238000001514 detection method Methods 0.000 claims abstract description 16
- 238000004422 calculation algorithm Methods 0.000 claims abstract description 14
- 238000004590 computer program Methods 0.000 claims description 7
- 238000012360 testing method Methods 0.000 claims description 4
- 239000000243 solution Substances 0.000 description 9
- 238000004891 communication Methods 0.000 description 8
- 238000010586 diagram Methods 0.000 description 8
- 230000006870 function Effects 0.000 description 7
- 230000008901 benefit Effects 0.000 description 6
- 230000008569 process Effects 0.000 description 6
- 238000012545 processing Methods 0.000 description 6
- 238000004458 analytical method Methods 0.000 description 5
- 230000006399 behavior Effects 0.000 description 3
- 238000010168 coupling process Methods 0.000 description 3
- 238000005859 coupling reaction Methods 0.000 description 3
- 238000013473 artificial intelligence Methods 0.000 description 2
- 238000004364 calculation method Methods 0.000 description 2
- 230000008878 coupling Effects 0.000 description 2
- 230000000694 effects Effects 0.000 description 2
- 230000009545 invasion Effects 0.000 description 2
- 238000012423 maintenance Methods 0.000 description 2
- 241001269238 Data Species 0.000 description 1
- 238000012550 audit Methods 0.000 description 1
- 230000005611 electricity Effects 0.000 description 1
- 238000005516 engineering process Methods 0.000 description 1
- 238000009415 formwork Methods 0.000 description 1
- 230000005484 gravity Effects 0.000 description 1
- 238000002347 injection Methods 0.000 description 1
- 239000007924 injection Substances 0.000 description 1
- 238000007689 inspection Methods 0.000 description 1
- 230000010354 integration Effects 0.000 description 1
- 230000033001 locomotion Effects 0.000 description 1
- 230000035800 maturation Effects 0.000 description 1
- 238000005259 measurement Methods 0.000 description 1
- 238000012986 modification Methods 0.000 description 1
- 230000004048 modification Effects 0.000 description 1
- 238000005192 partition Methods 0.000 description 1
- 230000002265 prevention Effects 0.000 description 1
- 230000009467 reduction Effects 0.000 description 1
- 230000004044 response Effects 0.000 description 1
- 238000000926 separation method Methods 0.000 description 1
- 238000012549 training Methods 0.000 description 1
Classifications
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F18/00—Pattern recognition
- G06F18/20—Analysing
- G06F18/24—Classification techniques
Landscapes
- Engineering & Computer Science (AREA)
- Data Mining & Analysis (AREA)
- Theoretical Computer Science (AREA)
- Computer Vision & Pattern Recognition (AREA)
- Bioinformatics & Cheminformatics (AREA)
- Bioinformatics & Computational Biology (AREA)
- Artificial Intelligence (AREA)
- Evolutionary Biology (AREA)
- Evolutionary Computation (AREA)
- Physics & Mathematics (AREA)
- General Engineering & Computer Science (AREA)
- General Physics & Mathematics (AREA)
- Life Sciences & Earth Sciences (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
- Information Retrieval, Db Structures And Fs Structures Therefor (AREA)
Abstract
Description
Claims (10)
Priority Applications (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201811206594.6A CN109325193B (zh) | 2018-10-16 | 2018-10-16 | 基于机器学习的waf正常流量建模方法以及装置 |
Applications Claiming Priority (1)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201811206594.6A CN109325193B (zh) | 2018-10-16 | 2018-10-16 | 基于机器学习的waf正常流量建模方法以及装置 |
Publications (2)
Publication Number | Publication Date |
---|---|
CN109325193A true CN109325193A (zh) | 2019-02-12 |
CN109325193B CN109325193B (zh) | 2021-02-26 |
Family
ID=65262696
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
CN201811206594.6A Active CN109325193B (zh) | 2018-10-16 | 2018-10-16 | 基于机器学习的waf正常流量建模方法以及装置 |
Country Status (1)
Country | Link |
---|---|
CN (1) | CN109325193B (zh) |
Cited By (8)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN111314291A (zh) * | 2020-01-15 | 2020-06-19 | 北京小米移动软件有限公司 | 网址安全性检测方法及装置、存储介质 |
CN111465055A (zh) * | 2020-03-30 | 2020-07-28 | 广西民族大学 | 一种数据挖掘算法受控切换消息的传输方法及系统 |
CN112351012A (zh) * | 2020-10-28 | 2021-02-09 | 杭州安恒信息技术股份有限公司 | 一种网络安全防护方法、装置及系统 |
CN112738109A (zh) * | 2020-12-30 | 2021-04-30 | 杭州迪普科技股份有限公司 | 一种Web攻击的检测方法及装置 |
CN113259303A (zh) * | 2020-02-12 | 2021-08-13 | 网宿科技股份有限公司 | 一种基于机器学习技术的白名单自学习方法和装置 |
CN113660244A (zh) * | 2021-08-11 | 2021-11-16 | 杭州安恒信息技术股份有限公司 | 网站可用性检测方法、系统、可读存储介质及装置 |
CN113839904A (zh) * | 2020-06-08 | 2021-12-24 | 北京梆梆安全科技有限公司 | 基于智能网联汽车的安全态势感知方法和系统 |
CN115622810A (zh) * | 2022-12-14 | 2023-01-17 | 深圳市永达电子信息股份有限公司 | 一种基于机器学习算法的业务应用识别系统及方法 |
Citations (3)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN107103171A (zh) * | 2016-02-19 | 2017-08-29 | 阿里巴巴集团控股有限公司 | 机器学习模型的建模方法及装置 |
CN107241352A (zh) * | 2017-07-17 | 2017-10-10 | 浙江鹏信信息科技股份有限公司 | 一种网络安全事件分类与预测方法及系统 |
CN107294993A (zh) * | 2017-07-05 | 2017-10-24 | 重庆邮电大学 | 一种基于集成学习的web异常流量监测方法 |
-
2018
- 2018-10-16 CN CN201811206594.6A patent/CN109325193B/zh active Active
Patent Citations (3)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN107103171A (zh) * | 2016-02-19 | 2017-08-29 | 阿里巴巴集团控股有限公司 | 机器学习模型的建模方法及装置 |
CN107294993A (zh) * | 2017-07-05 | 2017-10-24 | 重庆邮电大学 | 一种基于集成学习的web异常流量监测方法 |
CN107241352A (zh) * | 2017-07-17 | 2017-10-10 | 浙江鹏信信息科技股份有限公司 | 一种网络安全事件分类与预测方法及系统 |
Cited By (11)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN111314291A (zh) * | 2020-01-15 | 2020-06-19 | 北京小米移动软件有限公司 | 网址安全性检测方法及装置、存储介质 |
CN113259303A (zh) * | 2020-02-12 | 2021-08-13 | 网宿科技股份有限公司 | 一种基于机器学习技术的白名单自学习方法和装置 |
CN111465055A (zh) * | 2020-03-30 | 2020-07-28 | 广西民族大学 | 一种数据挖掘算法受控切换消息的传输方法及系统 |
CN111465055B (zh) * | 2020-03-30 | 2020-10-09 | 广西民族大学 | 一种数据挖掘算法受控切换消息的传输方法及系统 |
CN113839904A (zh) * | 2020-06-08 | 2021-12-24 | 北京梆梆安全科技有限公司 | 基于智能网联汽车的安全态势感知方法和系统 |
CN113839904B (zh) * | 2020-06-08 | 2023-08-22 | 北京梆梆安全科技有限公司 | 基于智能网联汽车的安全态势感知方法和系统 |
CN112351012A (zh) * | 2020-10-28 | 2021-02-09 | 杭州安恒信息技术股份有限公司 | 一种网络安全防护方法、装置及系统 |
CN112738109A (zh) * | 2020-12-30 | 2021-04-30 | 杭州迪普科技股份有限公司 | 一种Web攻击的检测方法及装置 |
CN113660244A (zh) * | 2021-08-11 | 2021-11-16 | 杭州安恒信息技术股份有限公司 | 网站可用性检测方法、系统、可读存储介质及装置 |
CN113660244B (zh) * | 2021-08-11 | 2023-02-24 | 杭州安恒信息技术股份有限公司 | 网站可用性检测方法、系统、可读存储介质及装置 |
CN115622810A (zh) * | 2022-12-14 | 2023-01-17 | 深圳市永达电子信息股份有限公司 | 一种基于机器学习算法的业务应用识别系统及方法 |
Also Published As
Publication number | Publication date |
---|---|
CN109325193B (zh) | 2021-02-26 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
CN109325193A (zh) | 基于机器学习的waf正常流量建模方法以及装置 | |
CN106709345B (zh) | 基于深度学习方法推断恶意代码规则的方法、系统及设备 | |
CN106992994B (zh) | 一种云服务的自动化监控方法和系统 | |
CN113645232B (zh) | 一种面向工业互联网的智能化流量监测方法、系统及存储介质 | |
JP2020501476A (ja) | ネットワークにおけるトラフィックの異常を検出するための方法および装置 | |
CN111741023A (zh) | 面向网络攻防试验平台的攻击研判方法、系统及介质 | |
CN107666410A (zh) | 网络安全分析系统 | |
CN103870751A (zh) | 入侵检测方法及系统 | |
US9491186B2 (en) | Method and apparatus for providing hierarchical pattern recognition of communication network data | |
CN110460608B (zh) | 一种包含关联分析的态势感知方法和系统 | |
CN106789904A (zh) | 物联网入侵检测方法及装置 | |
CN109873790A (zh) | 网络安全检测方法、装置以及计算机可读存储介质 | |
CN110162975A (zh) | 一种基于近邻传播聚类算法的多步异常点检测方法 | |
CN117240632A (zh) | 一种基于知识图谱的攻击检测方法和系统 | |
Li et al. | A lightweight intrusion detection model based on feature selection and maximum entropy model | |
CN111258874B (zh) | 一种基于web数据的用户操作轨迹分析方法及装置 | |
CN113032774A (zh) | 异常检测模型的训练方法、装置、设备及计算机存储介质 | |
CN106685946B (zh) | 一种物联网感知层入侵检测系统 | |
CN118764310A (zh) | 用于容器的攻击检测方法、装置、可读介质及电子设备 | |
US11232202B2 (en) | System and method for identifying activity in a computer system | |
CN117792727A (zh) | 威胁预警模型的训练及网络威胁预警方法、装置、设备 | |
CN117596052A (zh) | 一种面向电力网络复杂攻击行为的智能检测方法及系统 | |
KR101383069B1 (ko) | 네트워크 이상상태 탐지 장치 및 방법 | |
CN109446398A (zh) | 智能检测网络爬虫行为的方法、装置以及电子设备 | |
CN115189961B (zh) | 一种故障识别方法、装置、设备及存储介质 |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
PB01 | Publication | ||
PB01 | Publication | ||
SE01 | Entry into force of request for substantive examination | ||
SE01 | Entry into force of request for substantive examination | ||
CB02 | Change of applicant information |
Address after: No. 188, Lianhui street, Xixing street, Binjiang District, Hangzhou City, Zhejiang Province Applicant after: Dbappsecurity Co.,Ltd. Address before: 310000 15-storey Zhejiang Zhongcai Building, No. 68 Tonghe Road, Binjiang District, Hangzhou City, Zhejiang Province Applicant before: Dbappsecurity Co.,Ltd. |
|
CB02 | Change of applicant information | ||
GR01 | Patent grant | ||
GR01 | Patent grant | ||
EE01 | Entry into force of recordation of patent licensing contract |
Application publication date: 20190212 Assignee: Hangzhou Anheng Information Security Technology Co.,Ltd. Assignor: Dbappsecurity Co.,Ltd. Contract record no.: X2024980043368 Denomination of invention: Machine learning based WAF normal traffic modeling method and device Granted publication date: 20210226 License type: Common License Record date: 20241231 |
|
EE01 | Entry into force of recordation of patent licensing contract |