Network data security detection method and security detection server

A technology for security detection and network data, applied in the field of Internet security, to achieve rapid and effective identification, improve efficiency, and ensure network security

CN103634306BActive Publication Date: 2017-09-15三六零数字安全科技集团有限公司
3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Publication Date
2017-09-15

Smart Images

  • Figure 1
    Figure 1
  • Figure 2
    Figure 2
  • Figure 3
    Figure 3
Patent Text Reader

Abstract

The invention provides a network data safety detection method and a safety detection server. Among them, the security detection method of network data includes: grabbing the data packets transmitted in the network; grouping the data packets to restore the transmission control protocol TCP connection data, identifying the application layer protocol used by the TCP connection data; The security scanning module performs security scanning on TCP connection data. Utilize the technical scheme of the present invention, after grabbing data packets and grouping them, perform data security monitoring according to the application layer protocol corresponding to the data packets, and perform protocol analysis on the basis of the reorganized application layer protocol data, which is highly targeted and can Identify network attacks quickly and efficiently, improving network security.
Need to check novelty before this filing date? Find Prior Art

Description

technical field

[0001] The invention relates to the field of Internet security, in particular to a network data security detection method and a security detection server. Background technique

[0002] Malicious program is an umbrella term for any software program intentionally created to perform unauthorized and often harmful acts. Computer viruses, backdoor programs, keyloggers, password stealers, Word and Excel macro viruses, boot sector viruses, script viruses (batch, windows shell, java, etc.), Trojan horses, crimeware, spyware and adware, etc., These are examples of what could be called malicious programs.

[0003] Traditional anti-malware programs mainly rely on signature database matching or behavior analysis. The identification method of signature database matching is as follows: the antivirus engine reads the local file and matches all the signature code "keywords" in the signature database. If the file program code is found to be hit, it can be determined that th...

Examples

Embodiment Construction

[0039] The algorithms and displays presented herein are not inherently related to any particular computer, virtual system, or other device. Various generic systems can also be used with the teachings based on this. The structure required to construct such a system is apparent from the above description. Furthermore, the present invention is not specific to any particular programming language. It should be understood that various programming languages ​​can be used to implement the content of the present invention described herein, and the above description of specific languages ​​is for disclosing the best mode of the present invention.

[0040] figure 1 It is a schematic diagram of a network data security detection server 100 according to an embodiment of the present invention. As shown in the figure, the network data security detection server 100 generally includes: a data packet capture interface 110, a packet assembly device 120, and a protocol identification device 130...