Abnormal host detection method and device based on host portrait, medium and equipment
An abnormal host and detection method technology, applied in the computer field, can solve the problems of host definition and detection, and achieve the effects of more effective feature values, long decay period, and comprehensive detection dimensions
- Summary
- Abstract
- Description
- Claims
- Application Information
AI Technical Summary
Problems solved by technology
Method used
Image
Examples
Embodiment 1
[0078] Such as figure 1 As shown, according to the specific implementation manner of the present invention, in the first aspect, the present invention provides a method for detecting abnormal hosts based on host portraits, including:
[0079] Step S101: within the first set time segment, collect the first flow data of a plurality of host IPs to be tested based on the unsupervised learning method;
[0080] Among them, the unsupervised learning method is a method for solving various problems in pattern recognition based on training samples with unknown categories. In this embodiment, the IP flow data of the host to be tested is collected autonomously by the data collection device.
[0081] The first set time segment is an artificially set time period with an indefinite length, for example, including but not limited to daytime, night, working day, holiday, peak business period, fixed time period in the morning or afternoon of each day, etc.; A period of time can be set accordin...
Embodiment 2
[0131] Such as Figure 6 As shown, according to the specific embodiment of the present invention, in the second aspect, the present invention provides a device for detecting abnormal hosts based on host portraits, including: an acquisition unit 601, an extraction unit 602, a clustering unit 603, a processing unit 604, a merge Unit 605, training unit 606 and detection unit 607;
[0132] The collection unit 601 is configured to collect the first traffic data of a plurality of host IPs to be tested based on an unsupervised learning method within a first set time period;
[0133] The extracting unit 602 is configured to extract traffic characteristic values and host-associated characteristic values in the traffic data, wherein the traffic characteristic values include the number of upstream and downstream data and the number of upstream and downstream flows; the host-associated characteristic values include: Access port sequence, access IP sequence, access domain name seq...
Embodiment 3
[0176] Such as Figure 7 As shown, according to the specific implementation mode of the present invention, in the third aspect, this embodiment provides an electronic device, the device is used for a method for detecting an abnormal host based on a host image, and the electronic device includes: at least one processing and, a memory communicatively coupled to the at least one processor; wherein,
[0177] The memory stores instructions executable by the one processor, and the instructions are executed by the at least one processor, so that the at least one processor can perform: an abnormal host detection based on a host profile.
[0178] Refer below Figure 7 , which shows a schematic structural diagram of an electronic device 700 suitable for implementing the embodiments of the present disclosure. The terminal equipment in the embodiment of the present disclosure may include but not limited to such as mobile phone, notebook computer, digital broadcast receiver, PDA (persona...
PUM
Abstract
Description
Claims
Application Information
- R&D Engineer
- R&D Manager
- IP Professional
- Industry Leading Data Capabilities
- Powerful AI technology
- Patent DNA Extraction
Browse by: Latest US Patents, China's latest patents, Technical Efficacy Thesaurus, Application Domain, Technology Topic, Popular Technical Reports.
© 2024 PatSnap. All rights reserved.Legal|Privacy policy|Modern Slavery Act Transparency Statement|Sitemap|About US| Contact US: help@patsnap.com