A method and system for detecting network attack incidents
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-12
- Publication Date
- 2026-03-13
AI Technical Summary
Existing technologies are insufficient for efficiently detecting cyberattacks from massive amounts of network logs, and existing security measures have a high false alarm rate and are difficult to identify hidden backdoors left by attackers, making it difficult to uncover cyberattacks.
Network logs are generated by simulating known attack methods, constructing behavior sequences and direct follow-up relationships, building attack flowcharts using dependency metrics, and processing standardized network logs through ETL. Valid relationships are then filtered using thresholds, and the network log flowcharts are matched to determine attack events.
It improves the utilization rate of network log information, enables rapid identification of network attack events, reduces false alarm rates, and simplifies the tracing process for non-professional users.
Smart Images

Figure CN115643065B_ABST
Abstract
Citation Information
Patent Citations
Association analysis method of network security knowledge map based on space-earth integrated network
CN109005069A