Abnormal detection method and device based on host network behavior
A host network and anomaly detection technology, applied in the Internet field, can solve problems such as detection
- Summary
- Abstract
- Description
- Claims
- Application Information
AI Technical Summary
Problems solved by technology
Method used
Image
Examples
Embodiment 1
[0023] According to an embodiment of the present invention, a method embodiment of an anomaly detection method based on host network behavior is provided. It should be noted that the steps shown in the flow chart of the accompanying drawings can be implemented in a computer system such as a set of computer-executable instructions and, although a logical order is shown in the flowcharts, in some cases the steps shown or described may be performed in an order different from that shown or described herein.
[0024] figure 2 is an anomaly detection method based on host network behavior according to an embodiment of the present invention, such as figure 2 As shown, the method includes the following steps:
[0025] Step S102, collecting network behavior data of each host in at least one host according to historical abnormal network behavior.
[0026] Specifically, based on the network behaviors of existing attack samples, their common network behaviors, that is, abnormal network b...
Embodiment 2
[0053] According to an embodiment of the present invention, a product embodiment of an anomaly detection device based on host network behavior is provided, Figure 4 is an anomaly detection device based on host network behavior according to an embodiment of the present invention, such as Figure 4 As shown, the device includes an acquisition module 101 , an analysis module 103 , a determination module 105 and a matching module 107 .
[0054] Among them, the collection module 101 is used to collect the network behavior data of each host in at least one host according to the historical abnormal network behavior; Dimension data on each dimension in the data; Determining module 105 is used to determine the abnormal dimension data in the dimension data; Matching module 107 is used to match the abnormal dimension data with predefined rules for each host to determine whether an abnormal network occurs Behavior, and determine the abnormal network behavior corresponding to the abnorma...
PUM
Abstract
Description
Claims
Application Information
- R&D Engineer
- R&D Manager
- IP Professional
- Industry Leading Data Capabilities
- Powerful AI technology
- Patent DNA Extraction
Browse by: Latest US Patents, China's latest patents, Technical Efficacy Thesaurus, Application Domain, Technology Topic, Popular Technical Reports.
© 2024 PatSnap. All rights reserved.Legal|Privacy policy|Modern Slavery Act Transparency Statement|Sitemap|About US| Contact US: help@patsnap.com