Network abnormal behavior intelligent detection and response method and device and electronic equipment
A technology for intelligent detection and network anomalies, applied in the field of computer networks, can solve problems such as network single point failure, honeypot quantity and management inconvenience, and increase the delay of normal network access, so as to improve response speed, convenience and accuracy, The effect of delaying the attack process
- Summary
- Abstract
- Description
- Claims
- Application Information
AI Technical Summary
Problems solved by technology
Method used
Image
Examples
Example Embodiment
[0058] Example one
[0059] See figure 1 The present disclosure provides a network abnormal behavior intelligent detection and response method, which includes the following method steps:
[0060] Step S102: The mirror flow rate of the session layer is acquired by the switch, and the flow characteristics are extracted from the mirror traffic.
[0061] like figure 2 As shown, the mirror traffic interface of the network abnormal behavior intelligence detection and the response system is connected to the target network, and the mirror traffic data of the key session layer communication with this network is acquired by the subnet switch, and the mirror traffic data is received in the normal network service. The data is exactly the same, the mirror traffic data is used to generate subsequent detection rules and on the other hand for abnormal detection.
[0062] Wherein, the flow characteristics include, but are not limited to, the following types:
[0063] (1) IP / MAC address distribut...
Example Embodiment
[0100] Example 2
[0101] See Figure 7 The present disclosure provides a network abnormal behavior intelligent detection and response system, which is nestled through the entire network interactive system by hardware or software module. figure 2 As shown, the network access device acquires network data from the public network, and forwards network data to the server through the subnet switch to the server, and delivers data to network abnormal behavior intelligent detection and response system, network abnormal behavior intelligent detection and response system internal modules pass software Or the same functional module has the same technical effect as the embodiment, and will not be described herein, and the network abnormal behavior intelligent detection and response system specifically includes:
[0102] The extraction unit 702 is configured to capture the mirror flow of the session layer by the switch and extract flow characteristics from the mirror traffic.
[0103] Wherein,...
Example Embodiment
[0128] Example three
[0129] The present disclosure provides an electronic device including a processor and a memory, the memory stores a computer program command capable of executing by the processor, the processor performs the computer program command, realizing any one of the first aspect Method steps are described.
PUM
Abstract
Description
Claims
Application Information
- R&D Engineer
- R&D Manager
- IP Professional
- Industry Leading Data Capabilities
- Powerful AI technology
- Patent DNA Extraction
Browse by: Latest US Patents, China's latest patents, Technical Efficacy Thesaurus, Application Domain, Technology Topic.
© 2024 PatSnap. All rights reserved.Legal|Privacy policy|Modern Slavery Act Transparency Statement|Sitemap