An anomaly detection method and system based on reverse dns query attribute aggregation
A DNS query and anomaly detection technology, applied in transmission systems, electrical components, etc., can solve the problems of high false positive rate and low false negative rate.
- Summary
- Abstract
- Description
- Claims
- Application Information
AI Technical Summary
Problems solved by technology
Method used
Image
Examples
Embodiment Construction
[0049] Below in conjunction with accompanying drawing and specific embodiment the present invention is described in more detail:
[0050] Such as figure 1As shown, the anomaly detection method based on reverse DNS query attribute aggregation includes five parts: log collection and extraction, data aggregation, feature vector extraction, model training, and anomaly detection.
[0051] Specifically, first collect and extract the logs, filter out the DNS logs containing the PTR field, then collect the filtered reverse DNS query logs, and extract the effective information tuple Info=.
[0052] Carry out data aggregation then, in the scheme of the present invention, at first collect the reverse DNS query log that produces in the network security equipment, after extracting log feature, log is aggregated based on the attribute of target IP address, as figure 2 As shown, it is divided into two processes: horizontal aggregation and vertical aggregation. The specific process of horiz...
PUM
Login to View More Abstract
Description
Claims
Application Information
Login to View More 


