Unlock instant, AI-driven research and patent intelligence for your innovation.

Malicious webpage file identification method and device

A web page file and malicious web page technology, applied in the field of network security, can solve the problems of high false negative rate, difficult identification and high false positive rate

Active Publication Date: 2020-07-14
XIAMEN WANGSU CO LTD
View PDF4 Cites 2 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

[0003] In the prior art, there are mainly two ways to identify malicious webpage files: one is to match keywords through regular matching to detect malicious webpage files; this method has a low false positive rate, but a false negative rate High; usually the false positive rate can be controlled within 1-3%, but the false negative rate can reach 20% or even more than 30%
Another way is to use machine learning algorithms, such as random forest (random forest, RF) or deep learning network algorithms to classify malicious web files; although the false negative rate of this method can be reduced to 10% However, the false positive rate is relatively high, about 5-10%; and since non-malicious webpage file samples account for the majority of the total samples in practical applications, a false positive rate of 5-10% will generate a large number of False positives bring difficulties to subsequent screening

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Malicious webpage file identification method and device
  • Malicious webpage file identification method and device
  • Malicious webpage file identification method and device

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0043] In order to make the purpose, technical solutions and advantages of the present invention clearer, the present invention will be further described in detail below in conjunction with the accompanying drawings. Obviously, the described embodiments are only some of the embodiments of the present invention, rather than all of them. Based on the embodiments of the present invention, all other embodiments obtained by persons of ordinary skill in the art without making creative efforts belong to the protection scope of the present invention.

[0044] figure 1 A system framework for identifying malicious webpage files provided by the embodiment of the present invention, the webpage server 101 screens out the webpage files to be identified in the webpage files; and sends the webpage files to be identified to the rule engine server 102, and the rule engine server 102 The webpage file to be identified is identified to obtain a preliminary recognition result; the webpage server 10...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

PUM

No PUM Login to View More

Abstract

Embodiments of the invention provide a malicious webpage file identification method and device. The method comprises the steps of determining feature data of each dimension of a to-be-identified webpage file, wherein each dimension comprises a combined dimension and a single dimension, the combined dimension comprises a plurality of feature data, the single dimension is only one piece of feature data; for the combined dimension in each dimension, processing the plurality of feature data of the combined dimension through a first machine learning model to obtain fused feature data of the combined dimension; obtaining a preliminary identification result of whether the to-be-identified webpage file is a malicious webpage file or not through a rule engine; and processing the preliminary identification result, the fusion feature data of the combined dimension and the feature data of the single dimension through a second machine learning model to obtain a final result whether the to-be-identified webpage file is a malicious webpage file or not. By adopting the method, the accuracy of malicious webpage file identification is improved, and the security of a computer environment is greatly improved.

Description

technical field [0001] The present application relates to the technical field of network security, in particular to a method and device for identifying malicious webpage files. Background technique [0002] With the rapid development of communication networks, the Internet has spread rapidly. Until today, the Internet has had a close or even inseparable relationship with life. But then comes the cybersecurity problem that almost everyone faces. For example, there is a webpage script trojan (webshell), which is a command execution environment in the form of malicious webpage files such as asp, php, and jsp, and can be used as a webpage backdoor; This type of malicious webpage file will be mixed with normal webpage files in the website server directory, thereby destroying the normal operation of the computer or stealing privacy. Correspondingly, in order to protect the computer from being damaged by malicious webpage files, it is necessary to identify the malicious webpage f...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

Application Information

Patent Timeline
no application Login to View More
IPC IPC(8): G06F21/56G06F21/51G06N20/00G06K9/62
CPCG06F21/563G06F21/562G06F21/51G06N20/00G06F2221/2119G06F2221/033G06F18/253
Inventor 刘卓龙
Owner XIAMEN WANGSU CO LTD