Warning association method and device

An attacker and behavior technology, applied in the field of data security, can solve problems such as being unfavorable to discover the attacker's attack intention
CN106911629AActive Publication Date: 2017-06-30CHINA MOBILE COMM GRP CO LTD

Patent Information

Authority / Receiving Office
CN · China
Current Assignee / Owner
CHINA MOBILE COMM GRP CO LTD
Publication Date
2017-06-30

Smart Images

  • Figure 1
    Figure 1
  • Figure 2
    Figure 2
  • Figure 3
    Figure 3
Patent Text Reader

Abstract

The invention provides a warning association method and device. The problems that the real attack intention of an attacker cannot be easily discovered since the existing network attack frequently combines multiple tools and methods to implement multistep attack in a certain time and space span, but the WAF warning only aims at the single attack behavior is solved. The method comprises the following steps: obtaining attack behavior information according to a WAF warning log of an application firewall; acquiring attack mode information of the attacker according to the attack behavior information, wherein the attack mode information comprises attack type information corresponding to each attack behavior in an attack process of the attacker; associating the different attackers according to the similarity between the attack mode information of different attackers. By use of the warning association method provided by the invention, multiple disperse fine-grained attack behaviors in a logic relation are combined as a coarse-grained attack process, thereby providing basis and convenience for eliminating redundant warning, reappearing an attack scene, analyzing the attack intention of the attacker and other related works.
Need to check novelty before this filing date? Find Prior Art

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More