Multi-element behavior detection method and system based on hyper-converged server system, and medium
A server system and detection method technology, applied in the field of multi-behavior detection based on hyper-converged server system, can solve the problems of difficult to cover network behavior, difficult to detect intrusion behavior, large system overhead, etc., achieve easy deployment, reduce resource consumption, improve The effect of accuracy
- Summary
- Abstract
- Description
- Claims
- Application Information
AI Technical Summary
Problems solved by technology
Method used
Image
Examples
Embodiment 1
[0091] The method of the present invention includes the following modules:
[0092] Acquisition module: used to collect network behavior characteristics between virtual machines in the cluster of hyper-converged server systems, and capture the frequency of various network behaviors between virtual machines by modifying the protocol between virtual machines in the cluster;
[0093] Storage module: used to store the network behavior characteristics among virtual machines in the cluster of hyper-converged server systems, count the frequency of use of various network behaviors in a fixed total amount, and collect the access density maps of various network behaviors by using the network behavior capture function storing, the access density map is used as a data source for building a model module to describe network behavior;
[0094] Model building module: used to build a network behavior model among virtual machines in the cluster of the hyper-converged server system. The construc...
Embodiment 2
[0127] The multi-behavior detection method based on the hyper-converged server system provided by the embodiment of the present invention analyzes the characteristics of the network behavior between virtual machines from the exploit mechanism of the vulnerability, and selects various network behavior frequencies as the network behavior characteristics between virtual machines , use the collector to collect protocol messages corresponding to network behavior, extract network behavior characteristics between virtual machines, select and design appropriate dimensionality reduction and clustering algorithms, process data of network behavior characteristics between virtual machines, and construct normal virtual machines of the system Take the hyper-converged server as an example to build an attack detection system and design corresponding test modules to evaluate the performance of the attack detection system.
[0128] as attached figure 2 As shown, the multiple behavior detection...
PUM
Login to View More Abstract
Description
Claims
Application Information
Login to View More 


