Method and device for identifying IP gang, medium and equipment

A group and preset time period technology, applied in the field of Web network security, can solve the problems of high risk of misjudgment, low similarity of user behavior, and poor interpretability, so as to ensure accuracy, explainability and flexibility sexual effect
CN112800419APending Publication Date: 2021-05-14BEIJING SHU AN XINYUN TECH CO LTD

Patent Information

Authority / Receiving Office
CN Β· China
Patent Type
Applications(China)
Current Assignee / Owner
BEIJING SHU AN XINYUN TECH CO LTD
Publication Date
2021-05-14

Smart Images

  • Figure 1
    Figure 1
  • Figure 2
    Figure 2
  • Figure 3
    Figure 3
Patent Text Reader

Abstract

The invention relates to a method and device for identifying an IP gang, a medium and equipment, and the method for identifying the IP gang comprises the steps of obtaining a URL accessed by each IP and N behavior characteristics based on log data in a preset time period; aggregating all the IPs into different clusters based on the URL accessed by each IP and the N behavior characteristics; and when the cluster satisfies a preset condition, determining that the user corresponding to the IP in the cluster is an IP gang. According to the invention, more accurate gang clustering is realized for user behaviors of web logs, users with similar accessed URLs and similar access behaviors within a period of time are aggregated together, the accuracy of a clustering result is ensured, the method is also effective for low-frequency gangs, and the interpretability and flexibility of an identification result are ensured through specific rule parameters.
Need to check novelty before this filing date? Find Prior Art

Description

technical field

[0001] This article relates to Web network security, and in particular to methods, devices, media and equipment for identifying IP gangs. Background technique

[0002] IP gang behavior, that is, a group of organized robots that carry out attacks together over a period of time. In web security, the industry generally uses Internet traffic data collected by security devices, and uses data mining algorithms to analyze abnormal user behaviors, such as CC attacks, crawlers, and SQL injections.

[0003] In related technologies, existing web application firewalls usually analyze abnormal user behaviors by analyzing offline web logs and using data mining algorithms. Currently, there is no relatively mature solution for identifying specific gang behaviors. Existing web application firewalls are weak in identifying low-frequency group behaviors, the accuracy rate is not high, and the risk of misjudgment is high. As a result of the identified gang behavior, the simila...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More