Unlock instant, AI-driven research and patent intelligence for your innovation.

Method and system for detecting abnormal IP of mail system

A technology of mail system and detection method, which is applied in the detection method and detection system field of abnormal IP of mail system, can solve the problems of no consideration, the inability to accurately detect the abnormal IP of mail system, and the failure to consider the detection impact as a whole, so as to achieve improvement The effect of accuracy

Active Publication Date: 2021-12-17
COMP NETWORK INFORMATION CENT CHINESE ACADEMY OF SCI
View PDF5 Cites 0 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

[0003] However, some existing literatures do not consider the information in the alarm log of security devices in the same time period when judging abnormal IPs. In fact, malicious IPs may also attack the mail system network while attacking the mail system; some literatures judge When abnormal IP, although several different characteristics of abnormal IP are considered, the impact of different characteristics in detecting abnormal IP is not considered as a whole. Therefore, the methods disclosed in the prior art cannot accurately detect Abnormal IP

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Method and system for detecting abnormal IP of mail system
  • Method and system for detecting abnormal IP of mail system
  • Method and system for detecting abnormal IP of mail system

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0025] Wherein some embodiments of the present invention provide a kind of detection method of abnormal IP of mail system, this detection method comprises the following steps:

[0026] 1) Clean the mail log data and extract useful information;

[0027] Wherein, the cleaning purpose of the mail log data in step 1) is to remove the influence of noise and extract useful information. The useful information includes: login time, login IP, login IP attribution (used as geographic location information), operated email account name, Account login status (login success / login failure), abnormal operation period of login IP (query IP attribution local time 0:00-6:00);

[0028] 2) Statistics of the operation behavior data of the IP corresponding to each useful information within the preset time window to the mailbox account;

[0029] Wherein, the operation behavior data includes: the number of IP address operation accounts, the abnormal value of the number of login failures, the abnormal...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

PUM

No PUM Login to View More

Abstract

The invention provides a mail system abnormal IP detection method and system, and the method comprises the steps: cleaning mail log data, and extracting useful information; performing statistics on operation behavior data of the IP corresponding to each piece of useful information on the mailbox account in a preset time window; determining the weight occupied by each piece of operation behavior data in the current time window; calculating an IP behavior abnormal value z according to each operation behavior data and the corresponding weight, comparing the IP behavior abnormal value z with a preset threshold value z0, and when z is greater than z0, judging that the IP is an abnormal IP; according to the method, factors such as the number of IP address operation accounts in a mail system, the number of login failures and the condition of operating mailbox accounts in an abnormal time period are comprehensively considered, various influence factors are weighted, and the weight of each influence factor is learned by using a linear regression algorithm; and meanwhile, whether the IP address is the malicious IP or not is comprehensively judged by comparing the attack source IP address involved in the IDS equipment alarm log in the same time window, so that the accuracy of abnormal IP detection is improved.

Description

technical field [0001] The invention belongs to the field of abnormality detection, and in particular relates to a detection method and detection system for an abnormal IP in a mail system. Background technique [0002] E-mail is an indispensable communication tool for daily life and office work. Users can log in to e-mail through computers and other methods. However, with the continuous development of the network, the security of e-mail accounts is particularly important. However, the mail system is often attacked by malicious IPs, for example, brute force cracking of the mailbox accounts in the system, or stealing the content of the mails in the accounts (that is, the accused mailbox accounts) that have mastered the user name and password. Therefore, when suspicious behaviors occur, it is necessary to find these abnormal IPs in time for key monitoring, and block the access and operation of abnormal IPs to accounts in the mail system if necessary. [0003] However, some e...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

Application Information

Patent Timeline
no application Login to View More
Patent Type & Authority Applications(China)
IPC IPC(8): H04L29/06H04L12/58
CPCH04L63/1408H04L63/1425H04L63/0236H04L51/42Y02D10/00
Inventor 龙春杜冠瑶万巍赵静杨帆
Owner COMP NETWORK INFORMATION CENT CHINESE ACADEMY OF SCI