A method and system for detecting network attack incidents

CN115643065BActive Publication Date: 2026-03-13中孚安全技术有限公司
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-10-12
Publication Date
2026-03-13

AI Technical Summary

Technical Problem

Existing technologies are insufficient for efficiently detecting cyberattacks from massive amounts of network logs, and existing security measures have a high false alarm rate and are difficult to identify hidden backdoors left by attackers, making it difficult to uncover cyberattacks.

Method used

Network logs are generated by simulating known attack methods, constructing behavior sequences and direct follow-up relationships, building attack flowcharts using dependency metrics, and processing standardized network logs through ETL. Valid relationships are then filtered using thresholds, and the network log flowcharts are matched to determine attack events.

Benefits of technology

It improves the utilization rate of network log information, enables rapid identification of network attack events, reduces false alarm rates, and simplifies the tracing process for non-professional users.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115643065B_ABST
    Figure CN115643065B_ABST
Patent Text Reader

Abstract

This invention discloses a method and system for detecting network attack events, comprising: simulating attack events based on known attack methods and acquiring network logs of the simulated attack events; constructing a behavior sequence from the network logs of each simulated attack event under the same attack method to obtain an attack sequence for each attack method; constructing a set of direct follow relationships based on the direct follow relationships between behaviors in the attack sequence, and obtaining a dependency metric based on the direct follow frequency; constructing an attack flowchart based on the dependency metric and the direct follow frequency; constructing a network log flowchart from the acquired network logs to be tested; matching the network log flowchart with the attack flowchart; and determining whether a network attack event has occurred based on the matching result. Mining network attack events based on network logs solves the problem of difficulty in directly interpreting attack information from network logs and improves the utilization rate of information such as network logs.
Need to check novelty before this filing date? Find Prior Art

Citation Information

Patent Citations

  • Association analysis method of network security knowledge map based on space-earth integrated network

    CN109005069A