Collaborative defense method based on IOC intelligent extraction and sharing

A collaborative defense and intelligent technology, applied in transmission systems, electrical components, etc., can solve problems such as high false alarm rate, high hardware resource requirements, and untimely maintenance, and achieve slow resource consumption, less resource consumption, and high detection capabilities. Effect

Active Publication Date: 2020-01-10
HANGZHOU ANHENG INFORMATION TECH CO LTD
View PDF10 Cites 0 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

[0005] Whether it is deep machine learning or behavior analysis and detection, because it involves a large number of calculations such as classification and clustering, it requires high hardware resources; and in order to discover and capture more abnormal behaviors, it is necessary to correlate various network or system behaviors in a long period of time. Analysis, there are characteristics of relatively low detection performance and efficiency
[0006] At the same time, on different individual detection devices of the same type, due to various reasons such as untimely maintenance, inability to upgrade the new and old versions smoothly, and different hardware specifications, there are widespread problems of inconsistent versions and detection strategies, and great differences in detection capabilities. All detection capabilities of a single detection device come from the computing power of the device itself. The detection capabilities of old versions and old devices are weak, and there are problems of high false negative rate or easy bypassing

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Collaborative defense method based on IOC intelligent extraction and sharing
  • Collaborative defense method based on IOC intelligent extraction and sharing

Examples

Experimental program
Comparison scheme
Effect test

Embodiment 1

[0041] Embodiment 1, based on the collaborative defense method of IOC intelligent extraction and sharing, such as figure 2 Shown; including cloud IOC intelligence center module and single detection device module.

[0042] The cloud IOC intelligence center module includes an IOC collection and filtering module and an IOC sharing distribution module:

[0043] IOC collection and filtering module: According to the version number, IOC and corresponding threat information sent by each single detection device (such as single detection device A and single detection device B), match and update the existing IOC in the cloud IOC intelligence center module Or add a shared distribution IOC intelligence library. The above version number refers to the software version number in the individual detection device, which is set by the software installation or upgrade process; the above IOC refers to the individual detection device, based on the file Hash, domain name, IP and other data in the d...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

PUM

No PUM Login to view more

Abstract

The invention provides a collaborative defense method based on IOC intelligent extraction and sharing. The collaborative defense method comprises the following steps: S1) an IOC extraction and uploading module on a single detection device uploads extracted latest IOC data to an IOC acquisition and filtering module of a cloud IOC information center module; S2) the IOC acquisition and filtering module of the cloud IOC information center module allows the latest IOC data to match the existing IOC in the cloud IOC information center module, updates or newly adds a shared distribution IOC information library, and notifies the IOC to change data to an IOC shared distribution module of the cloud IOC information center module; S3) the IOC synchronization module of the single detection device synchronizes the latest IOC from the IOC shared distribution module of the cloud IOC intelligence center; and S4) the IOC detection module of the single detection device performs matching detection on thenetwork behavior according to the IOC to generate an alarm. According to the invention, a collaborative defense system with higher detection capability and less resource consumption can be formed.

Description

technical field [0001] The invention relates to an IOC intelligent extraction and sharing method, in particular to a collaborative defense method based on IOC intelligent extraction and sharing. Background technique [0002] Network attacks tend to be professionalized and industrialized, and intrusion methods are becoming more diverse and complex. New network attack methods and unknown threats make the defense system gradually adopt detection methods such as deep machine learning and behavior analysis. [0003] Whether it is deep machine learning or behavior analysis detection, compared with the traditional detection method based on known rules, it will consume more hardware resources. On the same single detection device, it will be reflected in poorer detection performance. At the same time, due to various reasons such as untimely maintenance, unsmooth upgrade of new and old versions, and different hardware specifications on different single detection devices of the same ty...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

Application Information

Patent Timeline
no application Login to view more
Patent Type & Authority Applications(China)
IPC IPC(8): H04L29/08H04L29/06
CPCH04L67/10H04L67/1095H04L63/0227H04L63/1441
Inventor 李凯范渊
Owner HANGZHOU ANHENG INFORMATION TECH CO LTD
Who we serve
  • R&D Engineer
  • R&D Manager
  • IP Professional
Why Eureka
  • Industry Leading Data Capabilities
  • Powerful AI technology
  • Patent DNA Extraction
Social media
Try Eureka
PatSnap group products