APT event homology judgment method based on behavior pattern
A judgment method and behavior technology, applied in the field of network security, can solve the problems of one-sided analysis results, low efficiency of artificial homology judgment, etc., and achieve the effect of good classification effect.
- Summary
- Abstract
- Description
- Claims
- Application Information
AI Technical Summary
Problems solved by technology
Method used
Image
Examples
Embodiment Construction
[0031] In order to better understand the contents of the present invention, an example is given here.
[0032] figure 1 It is an APT event correlation diagram based on behavior patterns in the present invention; figure 2 It is a schematic diagram of the implementation process of the present invention; image 3 It is a schematic diagram of attack clues and behavior patterns of the present invention; Figure 4 It is the APT event homology discrimination process of the present invention.
[0033] The invention discloses a method for judging the homology of APT events based on behavior patterns, the steps of which include:
[0034] S1, building an APT event correlation diagram based on behavior patterns;
[0035] Extract the clue information of APT events from the unstructured data obtained from multiple channels, extract the attack chain data of APT events from the kill chain model, and extract the technical and tactical information of this APT event from the attack technica...
PUM
Abstract
Description
Claims
Application Information
- R&D Engineer
- R&D Manager
- IP Professional
- Industry Leading Data Capabilities
- Powerful AI technology
- Patent DNA Extraction
Browse by: Latest US Patents, China's latest patents, Technical Efficacy Thesaurus, Application Domain, Technology Topic, Popular Technical Reports.
© 2024 PatSnap. All rights reserved.Legal|Privacy policy|Modern Slavery Act Transparency Statement|Sitemap|About US| Contact US: help@patsnap.com