Network malicious attack monitoring method and system based on deep neural model

The network malicious attack monitoring method that combines deep neural models with security sandboxes and graph convolutional networks solves the problem of insufficient identification of new and advanced threats by traditional static detection methods, realizes dynamic analysis and adaptive defense of complex attacks, and adapts to the network security needs of cloud computing and the Internet of Things.

CN119603031BActive Publication Date: 2025-09-16WUHAN MINGJIAXIN TECHNOLOGY CO LTD
0 Cites 0 Cited by

Patent Information

Application Number
CN202411723591.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-28
Publication Date
2025-09-16
Estimated Expiration
2044-11-28

AI Technical Summary

Technical Problem

Traditional static detection methods are unable to effectively deal with new and advanced network threats, especially unlisted malware and complex attack patterns.

Method used

A network malicious attack monitoring method based on deep neural models is adopted, combined with convolutional neural networks, recurrent neural networks, security sandbox environments and graph convolutional networks, to dynamically analyze program code behavior, identify potential attack chains and threat levels through network security knowledge graphs, and achieve adaptive learning and continuous optimization.

Benefits of technology

It effectively identifies and defends against new and advanced threats, improves the ability to identify unknown threats, adapts to the expansion of attack surfaces brought about by emerging technologies such as cloud computing and the Internet of Things, and achieves panoramic insight and continuous optimization of complex multi-stage attacks.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader

Abstract

The present application discloses a network malicious attack monitoring method and system based on a deep neural model, the method comprising: receiving unknown program code and performing feature matching on the unknown program code; if a known malicious program code feature is matched, marking the unknown program code as high-risk program code and inputting it into a first neural network model to obtain deep features; looping the high-risk program code to obtain a hard-coded seed value and a malicious behavior pattern; if the malicious behavior pattern is a DGA pattern, determining a DGA domain name list according to the seed value; inputting the domain name list into a hybrid model to obtain local semantic information; mapping the deep features, malicious behavior patterns, DGA domain names and local semantic information into a network security knowledge graph to obtain an event graph; analyzing the event graph to determine potential attack chains and threat levels, updating loop steps and graph reasoning steps, and dynamically loading them into an execution unit to display potential attack chains and threat levels.
Need to check novelty before this filing date? Find Prior Art