Method and device for constructing passive multi-dimensional host fingerprint model in network environment
A technology of network environment and construction method, which is applied in the field of passive multi-dimensional host fingerprint model construction, can solve the problems of lowering the accuracy of identifying the host, misjudgment, etc., and achieves the effect of reducing CPU burden, ensuring accuracy, and improving processing capacity
- Summary
- Abstract
- Description
- Claims
- Application Information
AI Technical Summary
Problems solved by technology
Method used
Image
Examples
Embodiment 1
[0039] Embodiment one, see figure 1 As shown, a passive multi-dimensional host fingerprint model construction device in a network environment includes:
[0040] The network traffic interception and screening model is used to initially screen and filter the original network traffic through the five-tuple strategy;
[0041] The host feature information identification and extraction module is used to extract multi-dimensional host feature information through different types of plug-ins. The plug-in types include at least: host hardware feature analysis, host software environment feature analysis, and host network behavior feature analysis. Different types of plug-ins correspond to corresponding hosts Identifying features of feature information;
[0042] The host fingerprint library building module builds a multi-dimensional host fingerprint library for host identification based on the MAP-SCORE algorithm.
[0043] Due to the diversity of host feature information, for a host, due ...
Embodiment 2
[0044] Embodiment two, such as Figure 1~2 As shown, it is basically the same as Embodiment 1, the difference is that: the host fingerprint database construction module includes:
[0045] A host feature matrix construction unit, configured to construct a host feature matrix storing feature information through the MAP method;
[0046] The host fingerprint extraction unit adopts the SCORE method to evaluate the correlation degree of each feature in the host feature matrix corresponding to different hosts, and builds a multi-dimensional host fingerprint library for host identification.
[0047] see figure 2 As shown in Fig. 1, through the extraction of host feature information, the host feature information with many entries in different dimensions of the host is obtained. However, due to the regulations of the application protocol, the host feature information carried by different behaviors in the process of interaction between the host and the application program is not the sa...
Embodiment 3
[0048] Embodiment three, see Figure 1~3 As shown, a method for constructing a passive multi-dimensional host fingerprint model in a network environment includes the following content:
[0049] Preliminary screening and filtering of network data traffic;
[0050] Extract multi-dimensional host feature information through different types of plug-ins, wherein different types of plug-ins correspond to corresponding identification features in the identification feature library;
[0051] Based on the MAP-SCORE algorithm, the correlation degree of each feature information corresponding to different hosts is evaluated, and a multi-dimensional host fingerprint library for host identification is constructed.
[0052] The method is simple and easy to implement, can accurately and efficiently discover host characteristic information, provides a technical basis for comprehensive understanding of hosts and accurate identification of hosts, and has strong practical application value.
PUM

Abstract
Description
Claims
Application Information

- Generate Ideas
- Intellectual Property
- Life Sciences
- Materials
- Tech Scout
- Unparalleled Data Quality
- Higher Quality Content
- 60% Fewer Hallucinations
Browse by: Latest US Patents, China's latest patents, Technical Efficacy Thesaurus, Application Domain, Technology Topic, Popular Technical Reports.
© 2025 PatSnap. All rights reserved.Legal|Privacy policy|Modern Slavery Act Transparency Statement|Sitemap|About US| Contact US: help@patsnap.com