SMTP server protection method and device based on dynamic log analysis and medium

Through dynamic log analysis and multi-dimensional data screening, the malicious IP address segment of the SMTP server is accurately identified, which solves the problems of false ban and insufficient flexibility in the existing technology, and realizes efficient and automated SMTP server protection.

CN120281529APending Publication Date: 2025-07-08GUANGDONG COREMAIL COMPUTER TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510410701.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-02
Publication Date
2025-07-08

AI Technical Summary

Technical Problem

The existing SMTP server protection technology relies on static rules to adapt to brute-force cracking attacks initiated by distributed IP pools, resulting in false bans of normal users and lack of flexibility and intelligent analysis.

Method used

Through dynamic log analysis, the login log of the SMTP server is obtained, and the multi-dimensional data filtering and misjudgment exclusion mechanism is used to accurately identify malicious IP address segments, generate a list of malicious IP address segments, and update the blocking strategy in real time.

Benefits of technology

It improves the protection accuracy of SMTP servers, reduces false bans, effectively deals with distributed attacks, reduces maintenance costs, and realizes the automated management of protection rules.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120281529A_ABST
    Figure CN120281529A_ABST
Patent Text Reader

Abstract

The invention discloses an SMTP server protection method and device based on dynamic log analysis and a medium. The method comprises the steps of obtaining a login log of an SMTP server; and malicious login behavior judgment and misjudgment elimination are performed on the IP address fields in the login log to obtain a malicious IP address field list, and the access request of the specified IP address field to the SMTP server is blocked according to the malicious IP address field list. According to the SMTP server protection method and device based on dynamic log analysis and the medium, through deep analysis of the login log, malicious IP address fields can be accurately identified, legal behaviors and malicious attempts can be efficiently distinguished, and the false alarm probability is greatly reduced; and meanwhile, a misjudgment correction mechanism is integrated, so that a wrong sealing condition caused by a fixed rule or a normal user mode which is misjudged as a malicious behavior can be effectively prevented, the safety of the SMTP server is ensured, and the problem that the SMTP server is difficult to effectively protect can be solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to a method, device and medium for protecting an SMTP server based on dynamic log analysis. Background Art

[0002] As a key cornerstone of email transmission, the SMTP server plays a central role in the email sending process. Both individual and enterprise users can accurately deliver emails to the designated recipients with the help of the SMTP server. However, attackers will use numerous distributed IP addresses to simultaneously attempt various combinations of usernames and passwords, attempting to quickly break through the protection of the SMTP server and then perform malicious behaviors such as sending spam emails and stealing sensitive information. The current protection technologies for SMTP servers cover multiple aspects, mainly including implementing strict password policies, establishing an IP blacklist mechanism, introducing verification code verification, and deploying intrusion detection and prevention systems (IDS / IPS). These measures together constitute a solid line of defense for the security protection of the SMTP server.

[0003] Existing technologies mostly rely on fixed static rules and thresholds to identify malicious behaviors. However, this static approach may be difficult to adapt to the continuous evolution of attack methods. Especially when facing brute-force cracking attacks launched by a distributed IP pool, its response is not flexible enough. In addition, due to the setting of rules, some normal users may unfortunately be misidentified as attackers when performing high-frequency logins or using dynamic IP addresses, thus causing unnecessary false bans. Summary of the Invention

[0004] The present invention provides a method, device and medium for protecting an SMTP server based on dynamic log analysis to solve the problem of difficult to effectively protect the SMTP server.

[0005] To achieve the above object, the present application provides a method for protecting an SMTP server based on dynamic log analysis, including:

[0006] Obtaining the login logs of the SMTP server;

[0007] Judging malicious login behaviors and excluding misjudgments for the IP address segments in the login logs to obtain a list of malicious IP address segments, and blocking access requests from specified IP address segments to the SMTP server according to the list of malicious IP address segments.

[0008] The malicious login behavior determination technology of the present invention can accurately identify IP addresses based on various information in the login log; through comparative analysis, it can distinguish which IP addresses are malicious and which are legal. This accurate identification ability helps to reduce misjudgments and improve the accuracy of protection. By introducing the misjudgment exclusion mechanism, it can reduce the phenomenon of false bans caused by improper rule settings or normal user behaviors; this ensures that only truly malicious IP address segments will be included in the blacklist, thus avoiding interference and damage to normal users. Once the list of malicious IP address segments is determined, access requests from the specified IP address segments to the SMTP server can be blocked based on this information; this targeted blocking measure can directly and effectively prevent the occurrence of malicious behaviors, thereby protecting the security of the server. Moreover, the present invention can continuously adjust and optimize the determination rules and blocking strategies according to real-time data and behavior analysis, so as to better adapt to the ever-changing attack patterns and threat environments.

[0009] Compared with the prior art, by deeply analyzing the login log, the present invention can accurately identify malicious IP address segments, efficiently distinguish legal behaviors from malicious attempts, and greatly reduce the false alarm probability; at the same time, by integrating the misjudgment correction mechanism, it can effectively prevent the situation of false bans caused by fixed rules or normal user patterns being misjudged as malicious behaviors, thereby ensuring the security of the SMTP server, and thus can solve the problem of difficult to effectively protect the SMTP server.

[0010] As a preferred solution, malicious login behavior determination and misjudgment exclusion are performed on the IP address segments in the login log to obtain a list of malicious IP address segments, specifically:

[0011] Information extraction and data conversion are performed on the login log to obtain a first data set;

[0012] Multi-dimensional data screening is performed on the first data set to obtain a set of malicious login behaviors; among them, the multi-dimensional data screening includes time window dynamic scoring screening and login failure rate threshold screening;

[0013] IP address segments that meet the preset normal behaviors are excluded from the set of malicious login behaviors to obtain the list of malicious IP address segments composed of several malicious IP address segments.

[0014] This preferred solution adopts multi-dimensional data screening methods such as time window dynamic scoring screening and login failure rate threshold screening, which can more comprehensively evaluate the risks of login behaviors. Excluding IP address segments that meet the preset normal behaviors from the set of malicious login behaviors can further reduce the false alarm rate.

[0015] As a preferred solution, multi-dimensional data screening is performed on the first data set to obtain a set of malicious login behaviors, specifically:

[0016] In the first dataset, an IP address segment that meets any condition in the condition set is defined as a malicious IP address segment, and the malicious login behavior set composed of several such malicious IP address segments is obtained;

[0017] Among them, the condition set includes a first condition, a second condition, a third condition, and a fourth condition.

[0018] This preferred solution can reduce false positives and false negatives caused by a single condition being too loose or too strict by comprehensively considering multiple conditions to determine whether an IP address segment is malicious. Only when an IP address segment meets at least one condition will it be recognized as malicious, which increases the accuracy and reliability of the judgment.

[0019] As a preferred solution, the first condition is specifically:

[0020] According to the number of successful logins and the number of failed logins of an IP address segment within a specified time window, calculate the login failure rate for the corresponding time window to obtain the login failure rates within several time windows;

[0021] An IP address segment whose login failure rate exceeds a preset threshold within a preset time window is defined as an object that meets the first condition.

[0022] This preferred solution can quantitatively evaluate the login behavior risk of an IP address segment by calculating the login failure rate, so as to accurately identify potential malicious behavior sources. Moreover, by setting the time window and the login failure rate threshold, IP address segments that meet the conditions can be automatically and quickly screened out without manually reviewing the login logs one by one.

[0023] As a preferred solution, the second condition is specifically:

[0024] According to the preset business requirements, assign corresponding weights to different types of login failure reason categories;

[0025] For each IP address segment and each time window, calculate the weighted failure total score according to the number of occurrences of each login failure reason and the corresponding weight;

[0026] An IP address segment whose weighted failure total score exceeds a preset threshold within a preset time window is defined as an object that meets the second condition.

[0027] This preferred solution can more precisely evaluate the login behavior risk of an IP address segment by assigning weights to different types of login failure reasons. By comprehensively considering the number of occurrences and weights of login failure reasons and calculating the weighted failure total score, the sensitivity and accuracy of detection can be improved; moreover, by introducing the concepts of weights and weighted failure total scores, false positives and false negatives caused by abnormal single indicators can be reduced.

[0028] As a preferred solution, the third condition and the fourth condition are specifically as follows:

[0029] Define the IP address segment marked as an IP blacklist by several target services and with the number of marks exceeding a preset threshold as the object satisfying the third condition;

[0030] Define the IP address segment with a reputation score lower than a preset threshold as the object satisfying the fourth condition; wherein, the reputation score is obtained by scoring the login behavior of the IP address segment and whether it is marked by the target service.

[0031] This preferred solution can more effectively identify the IP address segments that are jointly considered problematic by multiple services by combining the blacklist marking information of multiple target services. This multi-party verification method improves the accuracy and reliability of identification. Through the reputation scoring system, continuous risk assessment can be carried out on the IP address segments, thereby effectively preventing potential security risks.

[0032] As a preferred solution, exclude the IP address segments conforming to the preset normal behavior from the malicious login behavior set to obtain the malicious IP address segment list composed of several malicious IP address segments, specifically as follows:

[0033] Exclude the IP address segments conforming to the preset normal behavior from the malicious login behavior set according to the whitelist, and exclude the IP address segments with a login failure rate lower than the preset threshold within a preset time period from the malicious login behavior set to obtain the malicious IP address segment list composed of several malicious IP address segments.

[0034] This preferred solution can exclude those IP address segments known to be normal or trustworthy through the whitelist mechanism, thus avoiding misclassifying them as malicious IPs. Excluding the IP address segments conforming to the preset normal behavior and the IP address segments with a relatively low login failure rate within a preset time period can significantly reduce the number of IP address segments that need to be further analyzed and processed, thereby reducing resource consumption and improving detection efficiency.

[0035] This application also provides an SMTP server protection device based on dynamic log analysis, including a data module and a protection module;

[0036] Wherein, the data module is used to obtain the login logs of the SMTP server;

[0037] The protection module is used to determine malicious login behaviors and exclude misjudgments for the IP address segments in the login logs to obtain a malicious IP address segment list, and block access requests from specified IP address segments to the SMTP server according to the malicious IP address segment list.

[0038] As a preferred solution, the protection module includes a data unit, a screening unit, and an exclusion unit;

[0039] Among them, the data unit is used to extract information and convert data from the login log to obtain a first data set;

[0040] The screening unit is used to perform multi-dimensional data screening on the first data set to obtain a malicious login behavior set; among them, the multi-dimensional data screening includes time window dynamic scoring screening and login failure rate threshold screening;

[0041] The exclusion unit is used to exclude IP address segments that meet the preset normal behaviors from the malicious login behavior set to obtain the malicious IP address segment list composed of several malicious IP address segments.

[0042] As a preferred solution, the screening unit is specifically:

[0043] In the first data set, an IP address segment that meets any condition in the condition set is defined as a malicious IP address segment, and the malicious login behavior set composed of several such malicious IP address segments is obtained;

[0044] Among them, the condition set includes a first condition, a second condition, a third condition, and a fourth condition.

[0045] As a preferred solution, the first condition is specifically:

[0046] According to the number of successful logins and the number of failed logins of an IP address segment within a specified time window, calculate the login failure rate for the corresponding time window to obtain the login failure rates within several time windows;

[0047] An IP address segment whose login failure rate exceeds the preset threshold within the preset time window is defined as an object that meets the first condition.

[0048] As a preferred solution, the second condition is specifically:

[0049] According to the preset business requirements, assign corresponding weights to different types of login failure reason categories;

[0050] For each IP address segment and each time window, calculate the weighted failure total score according to the number of occurrences of each login failure reason and the corresponding weight;

[0051] An IP address segment whose weighted failure total score exceeds the preset threshold within the preset time window is defined as an object that meets the second condition.

[0052] As a preferred solution, the third condition and the fourth condition are specifically:

[0053] Define the IP address segment that is marked as an IP blacklist by several target services and the number of times of being marked exceeds the preset threshold as the object that meets the third condition;

[0054] Define the IP address segment with a reputation score lower than the preset threshold as the object that meets the fourth condition; wherein, the reputation score is obtained by scoring the login behavior of the IP address segment and whether it is marked by the target service.

[0055] As a preferred solution, the exclusion unit is specifically:

[0056] Exclude the IP address segments that meet the preset normal behavior from the malicious login behavior set according to the whitelist, and exclude the IP address segments with a login failure rate lower than the preset threshold within a preset time period from the malicious login behavior set, so as to obtain the malicious IP address segment list composed of several malicious IP address segments.

[0057] This application also provides a storage medium, on which a computer program is stored. The computer program is called and executed by a computer to implement the above-mentioned method for protecting an SMTP server based on dynamic log analysis. Description of the Drawings

[0058] Figure 1 is a schematic flowchart of a method for protecting an SMTP server based on dynamic log analysis provided by an embodiment of this application;

[0059] Figure 2 is a schematic regulation flowchart provided by an embodiment of this application;

[0060] Figure 3 is a schematic structural diagram of a device for protecting an SMTP server based on dynamic log analysis provided by an embodiment of this application. Detailed Embodiments

[0061] Next, the technical solutions in the embodiments of this application will be clearly and completely described in conjunction with the drawings in the embodiments of this application. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all the embodiments. Based on the embodiments in this application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of this application.

[0062] In the description of this application, it should be understood that the terms "first", "second", "third", and "fourth" are only used for descriptive purposes and cannot be construed as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, the features defined with "first", "second", "third", and "fourth" may explicitly or implicitly include one or more of such features. In the description of this application, unless otherwise specified, the meaning of "several" is two or more.

[0063] A method for protecting an SMTP server based on dynamic log analysis provided by an embodiment of this application aims to securely overcome the defects existing in the prior art, such as relying on static rules, high false positive and false negative rates, high manual maintenance costs, performance bottlenecks, and lack of intelligent analysis, and to ensure the security of the SMTP server.

[0064] Embodiment 1:

[0065] Please refer to Figure 1 , an embodiment of this application provides a method for protecting an SMTP server based on dynamic log analysis, including S1 to S3, and the specific implementation steps are as follows:

[0066] S1. Obtain the login logs of the SMTP server.

[0067] Specifically, step S1 of the embodiment of this application is:

[0068] Collect the login logs of the SMTP server through a containerized log collector and record the detailed information of each login attempt; among them, the containerized log collector is a real-time login log information collection tool designed specifically for email servers. It is built using container technology and, by configuring the Docker log driver, has the characteristics of convenient installation and use. By configuring the corresponding log functions, the containerized log collector can instantly obtain the login logs generated by the SMTP server and transmit this information to the subsequent processing links safely and efficiently;

[0069] Moreover, the "SMTP server" is a protocol server used to send and deliver emails; the "Docker log" refers to various log information generated during the operation of Docker containers, and this log information includes various types such as errors, warnings, and information. In addition, the "detailed information" includes, but is not limited to: source IP address, target email account, login timestamp, login result (success or failure), and reason for failure (such as: username does not exist, password error, authentication failure, etc.).

[0070] In this embodiment, S1 utilizes container technology and, by configuring the Docker log driver, can achieve lightweight and portable collection of logs.

[0071] S2. Determine malicious login behaviors and exclude misjudgments for the IP address segments in the login logs, obtain a list of malicious IP address segments, and block access requests from specified IP address segments to the SMTP server according to the list of malicious IP address segments.

[0072] Step S2 of the embodiment of the present application includes S2.1 to S2.3, specifically:

[0073] S2.1. Use a log parser to extract key information in the login logs, such as login time, logged-in IP address, username, and whether the login is successful or not;

[0074] Use a data format converter to convert the extracted key information into a standardized and easy-to-process format to obtain a first data set;

[0075] Store the first data set according to the log storage and systematically organize and arrange it in chronological order for subsequent efficient and organized query and in-depth analysis work; among them, "log storage" is used to store the organized log data.

[0076] S2.2. Use an IP segment identifier to perform preprocessing operations on the source IP addresses in the first data set. By intercepting the prefix part of the IP address (for example, taking its first 24 bits), use it as the unique identifier of the corresponding IP address segment in the first data set for subsequent accurate and efficient statistical analysis work; among them, the IP segment identifier is used to identify relevant IP address segments from the log data;

[0077] Use an attack behavior judge to perform corresponding processing operations on the first data set after preprocessing according to the specified data processing methods in the condition set, and in the first data set, define the IP address segments that meet any condition in the condition set as malicious IP address segments, and at the same time mark potential malicious login behaviors according to the high-risk area and high-risk ASN lists to obtain a malicious login behavior set composed of several malicious IP address segments and several potential malicious IP address segments; among them, the attack behavior judge is used to judge whether there is a malicious login behavior for a certain IP address segment according to the preset criteria;

[0078] Among them, the condition set includes the first condition, the second condition, the third condition, and the fourth condition; the high-risk area and high-risk ASN lists are carefully constructed based on the geographical location data (covering country and region information) of the IP address and its ASN (autonomous system number) information to identify the IP sources that may be involved in malicious login behaviors.

[0079] The following specifically describes each condition in the condition set:

[0080] ① The first condition:

[0081] Set diverse time windows, such as 1 minute, 5 minutes, 1 hour, and 24 hours, to capture the pattern features of login behaviors at different time granularities;

[0082] In the login behavior pattern, count the total number of login attempts, the number of successful logins, and the number of failed logins for each IP address segment within each time window;

[0083] According to the total number of login attempts, the number of successful logins, and the number of failed logins of an IP address segment within a specified time window, calculate the login failure rate for the corresponding time window to obtain the login failure rates within several time windows; where the login failure rate is the ratio of the number of failed logins to the total number of login attempts;

[0084] Define the IP address segments with a login failure rate exceeding the preset threshold within a preset time window (e.g., 1 minute) as the objects meeting the first condition.

[0085] ② The second condition:

[0086] Classify different types of login failure reasons, and assign corresponding weights to different types of login failure reason categories according to the preset business requirements and the potential maliciousness of each type of login failure reason to distinguish their potential malicious degrees; where the login failure reason categories specifically cover: username does not exist, password error, and other authentication failure situations;

[0087] For each IP address segment and each time window, calculate the weighted total failure scores caused by different failure reasons based on the number of occurrences of each login failure reason and the corresponding weights;

[0088] Define the IP address segments with a weighted total failure score exceeding the preset threshold (e.g., 20 points) within a preset time window (e.g., 5 minutes) as the objects meeting the second condition.

[0089] ③ The third condition:

[0090] Query the global RBL service (Real-time Blackhole List service, real-time blacklist service) in real time, and define the IP address segments marked as IP blacklists by several RBL services and with the number of marked times exceeding the preset threshold number (e.g., marked as IP blacklists by 3 RBL manufacturers) as the objects meeting the third condition, and incorporate the query results of the RBL service into the reputation score calculation;

[0091] Among them, the RBL services include Spamhaus, CBL, etc.; Spamhaus is an international non-profit organization focusing on tracking spam and related cyber threats, such as phishing, malware, and botnets; CBL is one of the real-time blacklist services provided by the China Anti-Spam Alliance (anti-spam.org.cn).

[0092] ④ Fourth condition:

[0093] Define the IP address segment with a reputation score lower than the preset threshold (e.g., 30 points) as the object that meets the fourth condition;

[0094] Among them, the reputation score is obtained by scoring the login behavior of the IP address segment and whether it is marked by the target service according to the IP address segment reputation scoring mechanism. Specifically:

[0095] Construct an IP address segment reputation scoring system for each IP address segment, and set the initial score to 100 points. This system dynamically adjusts the reputation score according to the login behavior of the IP address segment, and the adjustment rules are set in detail as follows:

[0096] 1) If a successful login occurs once, the reputation score increases by 1 point;

[0097] 2) If a login fails once due to a wrong password, the reputation score decreases by 1 point;

[0098] 3) If a login fails once due to a non-existent username, the reputation score decreases by 2 points;

[0099] 4) If a login fails once for other reasons, the reputation score decreases by 0.5 points;

[0100] 5) If it is marked by the RBL service, the reputation score is directly deducted by 50 points.

[0101] In this embodiment, S2.2 adopts multi-dimensional data screening methods such as time window dynamic scoring screening and login failure rate threshold screening, which can more comprehensively evaluate the risk of login behavior;

[0102] Moreover, by comprehensively considering multiple conditions to judge whether an IP address segment is malicious, the problem of false positives and false negatives caused by a single condition being too loose or too strict can be reduced. Only when the IP address segment meets at least one condition will it be identified as malicious, which increases the accuracy and reliability of the judgment;

[0103] For the first condition, by calculating the login failure rate, the risk of the login behavior of the IP address segment can be quantitatively evaluated to accurately identify potential malicious behavior sources. Moreover, by setting a time window and a login failure rate threshold, the IP address segments that meet the conditions can be automatically and quickly screened out without manual review of the login logs one by one; in addition, traditional technologies often rely on preset static rules and thresholds (such as the single IP banning strategy of Fail2ban). However, in this embodiment, by analyzing the login behavior patterns of IP segments and combining the dynamic thresholds of login success and failure, malicious IP segments can be more accurately and dynamically identified to effectively cope with the challenges of distributed attacks.

[0104] For the second condition, by assigning weights to different types of login failure reasons, the login behavior risk of IP address segments can be evaluated more precisely. By comprehensively considering the number and weight of login failure reasons and calculating the weighted total failure score, the sensitivity and accuracy of detection can be improved; moreover, by introducing the concepts of weight and weighted total failure score, false positives and false negatives caused by abnormal single indicators can be reduced;

[0105] For the third and fourth conditions, by combining the blacklist marking information of multiple target services, IP address segments that are commonly considered problematic by multiple services can be identified more effectively. This multi-party verification method improves the accuracy and reliability of identification. Through the reputation scoring system, continuous risk assessment can be carried out on IP address segments, thereby effectively preventing potential security risks.

[0106] S2.3. Use a false positive eliminator to exclude misjudgments of white lists, correct misjudgments based on historical behavior, and exclude misjudgments based on scenarios from the malicious login behavior set, obtaining several malicious IP address segments; the list of malicious IP address segments is composed of several malicious IP address segments remaining after data exclusion; among them, the false positive eliminator is used to exclude normal IP address segments to avoid misjudgment;

[0107] Sort out the list of finally confirmed malicious IP address segments, generate an instruction to update the block list and send it to the database, and use a rule updater to update the information of the IP address segments to be intercepted in the IP block list accordingly; among them, the rule updater is used to update the list of IP address segments that need to be blocked according to the analysis results;

[0108] Subsequently, according to the updated IP block list, block connection requests from these malicious IPs to ensure the security protection of the SMTP server; among them, the IP block list is used to store the information of IP address segments that need to be blocked.

[0109] The following makes a specific description of the exclusion method:

[0110] ① Exclude misjudgments of white lists: Exclude IP address segments that conform to preset normal behaviors from the malicious login behavior set according to static white lists and dynamic white lists;

[0111] Among them, the static white list is used to record known and trustworthy IP address segments, covering IP address segments such as enterprise internal mail servers and important partners' IP address segments, etc. These recorded IP address segments will be exempt from the review of the malicious login behavior identification mechanism;

[0112] The dynamic whitelist is used to automatically identify and record those IP address segments that have shown excellent performance over a long period. Specifically, the IP address segments that meet the following conditions will be included in the dynamic whitelist: the login success rate exceeds 95% within 30 consecutive days, the credit score remains above 90 continuously, and it has not been blacklisted by any RBL service;

[0113] ② Misjudgment correction based on historical behavior: For IP address segments where malicious login behaviors are collectively determined to be "potential malicious login behaviors", further analyze their historical login behaviors to determine whether there is a possibility of misjudgment, that is: if a certain IP address segment has mainly shown successful logins during a specific past time period, and the login failure rate remains below a relatively low threshold, for example, within the past 7 days, successful logins are dominant and the failure rate is below 5%, then remove this IP address segment from the set of malicious login behaviors;

[0114] ③ Misjudgment exclusion based on scenarios: In order to take into account the normal business requirements in different time periods, it is necessary to implement a dynamic adjustment strategy for the judgment threshold of malicious login behaviors, and accordingly remove some misjudged malicious IP addresses from the set of malicious login behaviors. Specifically, during regular working hours (such as 9:00 to 18:00), the judgment criteria will be appropriately relaxed to reduce interference with normal business activities;

[0115] Among them, the criteria for normal business requirements are formulated by fully considering the geographical location information (ASN) of the IP address segment. For IP address segments from different regions, different judgment criteria are adopted. For example, for the IP address segments in the core business area of an enterprise, the judgment threshold will be correspondingly relaxed to ensure the smooth progress of business.

[0116] To apply the embodiments of this application, please refer to Figure 2 , Figure 2 is the data interaction diagram provided by the embodiments of this application, showing the relationships between the modules and the data flow mode in this embodiment; among them, the security protection system includes a log collection module, a log processing module, a rule engine module, and a database module; the log collection module includes a containerized log collector; the log processing module includes a log parser, a data format converter, and log storage; the rule engine module includes an IP segment identifier, an attack behavior judge, a false alarm eliminator, and a rule updater; the database module includes an IP block list;

[0117] Among them, the specific interaction relationships between the modules are as follows:

[0118] When a user logs in to the email server, the mail service component will generate a login log;

[0119] The containerized log collector immediately captures this log information;

[0120] The collected logs are then sent to the log parser for processing;

[0121] The log parser extracts key information from them and passes it to the data format converter;

[0122] The data format converter is responsible for converting the information into a standard format and storing it in the log storage system;

[0123] The IP segment recognizer reads data from the log storage and identifies the corresponding IP address segments;

[0124] The attack behavior judge combines these IP address segments with the log data to evaluate whether there is a malicious login attempt;

[0125] The false alarm eliminator further screens and eliminates normal IP address segments;

[0126] The rule updater updates the IP block list in the database according to the final analysis conclusion;

[0127] The email server intercepts connection requests from malicious IPs based on the IP block list to ensure the security of the server.

[0128] In this embodiment S2.3, through the whitelist mechanism, those IP address segments known to be normal or trustworthy can be excluded, thus avoiding misclassifying them as malicious IPs. Excluding IP address segments that conform to the preset normal behavior and those with a low login failure rate within the preset time period can significantly reduce the number of IP address segments that need to be further analyzed and processed, thereby reducing resource consumption, improving detection efficiency, and further reducing the false alarm rate;

[0129] Moreover, traditional technologies ignore the false alarm problem, while this embodiment significantly improves the recognition accuracy by distinguishing normal services from potential malicious IP segments and automatically eliminating false alarms. Traditional technologies rely on manual updating of the rule blacklist, while this embodiment realizes the automated management of protection rules by automatically analyzing logs through a program and updating the IP block list in real time.

[0130] It should be noted that in this embodiment 1, Docker (container technology) and Elasticsearch (elastic search engine) are used for log collection and analysis; this embodiment uses Docker containerized deployment and the log analysis ability of Elasticsearch. By optimizing the log analysis and data processing process, it is possible to reduce the occupancy of system resources and ensure the normal operation of the SMTP server in a high-traffic environment.

[0131] Overall, this embodiment has the following beneficial effects:

[0132] The malicious login behavior determination technology of this application can accurately identify IP addresses based on various information in the login logs; through comparative analysis, it can distinguish which IP addresses are malicious and which are legitimate. This accurate identification ability helps to reduce misjudgments and improve the accuracy of protection. By introducing the mechanism of misjudgment exclusion, it is possible to reduce the phenomenon of misblocking caused by improper rule settings or normal user behaviors; this ensures that only truly malicious IP address segments will be added to the blacklist, thus avoiding interference and damage to normal users. Once the list of malicious IP address segments is determined, access requests from the specified IP address segments to the SMTP server can be blocked based on this information; this targeted blocking measure can directly and effectively prevent malicious behaviors from occurring, thereby protecting the security of the server. Moreover, this application can continuously adjust and optimize the determination rules and blocking strategies based on real-time data and behavior analysis, so as to better adapt to the changing attack patterns and threat environments;

[0133] In addition, this application uses dynamic IP segment behavior analysis to effectively defend against brute-force cracking of the SMTP server, especially distributed attacks. By comprehensively analyzing login attempts and IP segments, it can accurately identify malicious attacks, which goes beyond traditional single-IP detection. By intelligently comparing normal and potentially malicious IP segments and automatically excluding false positives, the protection accuracy is improved. At the same time, it can realize automatic updating of protection rules without manual intervention, quickly respond to new attack patterns, and reduce maintenance costs. Elasticsearch is used to process the logs, and its distributed architecture and efficient indexing ensure that massive logs can be processed quickly. Containerized deployment optimizes the system deployment process and expansion ability, thus ensuring the security, stability, and efficiency of the SMTP server protection.

[0134] Embodiment 2:

[0135] Please refer to Figure 3 , an embodiment of this application provides an SMTP server protection device based on dynamic log analysis, including a data module 10 and a protection module 20;

[0136] Among them, the data module 10 is used to obtain the login logs of the SMTP server;

[0137] The protection module 20 is used to determine malicious login behaviors and exclude misjudgments for the IP address segments in the login logs, obtain a list of malicious IP address segments, and block access requests from the specified IP address segments to the SMTP server according to the list of malicious IP address segments.

[0138] In one embodiment, the data module 10 is specifically:

[0139] Collect the login logs of the SMTP server through a containerized log collector and record the detailed information of each login attempt; among them, the containerized log collector is a real-time login log information collection tool designed specifically for email servers. It is built using container technology. By configuring the Docker log driver, it has the characteristics of convenient installation and use. By configuring the corresponding log functions, the containerized log collector can instantly obtain the login logs generated by the SMTP server and securely and efficiently transfer this information to subsequent processing links;

[0140] Moreover, the "SMTP server" is a protocol server used to send and transfer emails; "Docker logs" refers to various log information generated during the operation of Docker containers, and these log information include various types such as errors, warnings, and information. In addition, the "detailed information" includes but is not limited to: source IP address, target email account, login timestamp, login result (success or failure), reason for failure (such as: username does not exist, password error, authentication failure, etc.).

[0141] In this embodiment, the data module 10 uses container technology. By configuring the Docker log driver, it can achieve lightweight and portable collection of logs.

[0142] In one embodiment, the protection module 20 includes a data unit, a screening unit, and an exclusion unit;

[0143] Among them, the data unit is used to extract key information from the login logs using a log parser, such as login time, logged-in IP address, username, and whether the login is successful or not;

[0144] The data unit is also used to convert the extracted key information into a standardized and easy-to-process format using a data format converter to obtain a first data set;

[0145] The data unit is also used to store the first data set according to the log storage and systematically organize and arrange it according to the chronological order for subsequent efficient and organized query and in-depth analysis work; among them, the "log storage" is used to store the organized log data.

[0146] The screening unit is used to perform a preprocessing operation on the source IP addresses in the first data set using an IP segment identifier. By intercepting the prefix part of the IP address (for example, taking its first 24 bits), it is used as the unique identifier of the corresponding IP address segment in the first data set for subsequent accurate and efficient statistical analysis work; among them, the IP segment identifier is used to identify relevant IP address segments from the log data;

[0147] The screening unit is also used to use the attack behavior judge to perform corresponding processing operations on the first data set after preprocessing according to the specified data processing methods in the condition set, and in the first data set, define the IP address segments that meet any condition in the condition set as malicious IP address segments, and at the same time mark potential malicious login behaviors according to the high-risk regions and high-risk ASN lists, so as to obtain a malicious login behavior set composed of a number of malicious IP address segments and a number of potential malicious IP address segments; among them, the attack behavior judge is used to judge whether there is a malicious login behavior for a certain IP address segment according to the preset criteria.

[0148] Among them, the condition set includes the first condition, the second condition, the third condition and the fourth condition; the high-risk regions and high-risk ASN lists are carefully constructed based on the geographical location data (covering country and region information) of the IP addresses and their ASN (autonomous system number) information, aiming to identify the IP sources that may be involved in malicious login behaviors.

[0149] The following is a specific description of each condition in the condition set:

[0150] ① The first condition:

[0151] Set diverse time windows, such as 1 minute, 5 minutes, 1 hour and 24 hours, to capture the pattern characteristics of login behaviors at different time granularities;

[0152] In the login behavior pattern, count the total number of login attempts, the number of successful logins and the number of failed logins for each IP address segment within each time window;

[0153] According to the total number of login attempts, the number of successful logins and the number of failed logins of the IP address segment within the specified time window, calculate the login failure rate of the corresponding time window to obtain the login failure rates within a number of time windows; among them, the login failure rate is the ratio of the number of failed logins to the total number of login attempts;

[0154] Define the IP address segments with a login failure rate exceeding the preset threshold within the preset time window (such as 1 minute) as the objects that meet the first condition.

[0155] ② The second condition:

[0156] Classify different types of login failure reasons, and assign corresponding weights to different types of login failure reason categories according to the preset business requirements and the potential maliciousness of various login failure reasons to distinguish their potential malicious degrees; among them, the login failure reason categories specifically cover: non-existent username, wrong password and other authentication failure situations;

[0157] For each IP address segment and each time window, calculate the total weighted failure score caused by different failure reasons based on the number of occurrences of each login failure reason and the corresponding weights.

[0158] Define the IP address segments whose total weighted failure score exceeds a preset threshold (e.g., 20 points) within a preset time window (e.g., 5 minutes) as objects that meet the second condition.

[0159] ③ Third condition:

[0160] Query the global RBL service (Real-time Blackhole List service) in real time. Define the IP address segments that are marked as IP blacklists by several RBL services and the number of marked times exceeds a preset threshold number (e.g., marked as IP blacklists by 3 RBL manufacturers) as objects that meet the third condition, and incorporate the query results of the RBL service into the calculation of the reputation score.

[0161] Among them, the RBL services include Spamhaus, CBL, etc.; Spamhaus is an international non-profit organization focusing on tracking spam and related cyber threats such as phishing, malware, and botnets; CBL is one of the real-time blacklist services provided by the China Anti-Spam Alliance (anti-spam.org.cn).

[0162] ④ Fourth condition:

[0163] Define the IP address segments with a reputation score lower than a preset threshold (e.g., 30 points) as objects that meet the fourth condition.

[0164] Among them, the reputation score is obtained by scoring the login behavior of the IP address segment and whether it is marked by the target service according to the IP address segment reputation scoring mechanism. Specifically:

[0165] Construct an IP address segment reputation scoring system for each IP address segment, and set the initial score to 100 points. This system dynamically adjusts the reputation score according to the login behavior of the IP address segment, and the adjustment rules are set as follows in detail:

[0166] 1) For each successful login, the reputation score increases by 1 point;

[0167] 2) For each failed login due to a password error, the reputation score decreases by 1 point;

[0168] 3) For each failed login due to a non-existent username, the reputation score decreases by 2 points;

[0169] 4) For each failed login due to other reasons, the reputation score decreases by 0.5 point;

[0170] 5) Marked by the RBL service, the reputation score is directly deducted by 50 points.

[0171] In this embodiment, the screening unit adopts multi-dimensional data screening methods such as time window dynamic scoring screening and login failure rate threshold screening, which can more comprehensively evaluate the risk of login behavior;

[0172] Moreover, by comprehensively considering multiple conditions to determine whether an IP address segment is malicious, the problem of false positives and false negatives caused by a single condition being too loose or too strict can be reduced. Only when the IP address segment meets at least one condition will it be identified as malicious, which increases the accuracy and reliability of the judgment;

[0173] For the first condition, by calculating the login failure rate, the risk of the login behavior of the IP address segment can be quantitatively evaluated to accurately identify potential sources of malicious behavior. Moreover, by setting a time window and a login failure rate threshold, IP address segments that meet the conditions can be automatically and quickly screened out without manually reviewing the login logs one by one; in addition, traditional technologies often rely on preset static rules and thresholds (such as the single IP blocking strategy of Fail2ban). However, in this embodiment, by analyzing the login behavior patterns of the IP segment and combining the dynamic thresholds of login success and failure, malicious IP segments can be more accurately and dynamically identified to effectively cope with the challenges of distributed attacks.

[0174] For the second condition, by assigning weights to different types of login failure reasons, the risk of the login behavior of the IP address segment can be evaluated more precisely. By comprehensively considering the number of times and weights of the login failure reasons and calculating the weighted total failure score, the sensitivity and accuracy of the detection can be improved; moreover, by introducing the concepts of weights and weighted total failure scores, false positives and false negatives caused by a single abnormal indicator can be reduced;

[0175] For the third and fourth conditions, by combining the blacklist marking information of multiple target services, IP address segments that are considered problematic by multiple services can be more effectively identified. This multi-party verification method improves the accuracy and reliability of the identification. Through the reputation scoring system, continuous risk assessment can be carried out on the IP address segment to effectively prevent potential security risks.

[0176] The exclusion unit is used to use a false positive eliminator to exclude misjudgments of white lists, correct misjudgments based on historical behavior, and exclude misjudgments based on scenarios from the malicious login behavior set to obtain several malicious IP address segments; the malicious IP address segment list is composed of several malicious IP address segments remaining after data exclusion; among them, the false positive eliminator is used to exclude normal IP address segments to avoid misjudgment;

[0177] The exclusion unit is also used to sort out the list of finally confirmed malicious IP address segments, generate an instruction to update the block list and send it to the database, and use the rule updater to update the IP address segment information to be intercepted in the IP block list accordingly; among them, the rule updater is used to update the list of IP address segments that need to be blocked according to the analysis results.

[0178] The exclusion unit is also used to subsequently block connection requests from these malicious IPs based on the updated IP block list to ensure the security protection of the SMTP server; among them, the IP block list is used to store the IP address segment information that needs to be blocked.

[0179] The following is a specific description of the exclusion method:

[0180] ① Exclusion of misjudgments in the whitelist: Exclude IP address segments that meet the preset normal behaviors from the malicious login behavior set according to the static whitelist and the dynamic whitelist.

[0181] Among them, the static whitelist is used to record known and trustworthy IP address segments, covering IP address segments such as enterprise internal mail servers and important partners' IP address segments. These recorded IP address segments will be exempt from the review of the malicious login behavior recognition mechanism.

[0182] The dynamic whitelist is used to automatically identify and record those IP address segments with excellent long-term performance. Specifically, IP address segments that meet the following conditions will be included in the dynamic whitelist: the login success rate exceeds 95% within 30 consecutive days, the reputation score continuously remains above 90 points, and they are not listed in the blacklist by any RBL service.

[0183] ② Correction of misjudgments based on historical behaviors: For IP address segments in the malicious login behavior set that are determined to be "potentially malicious login behaviors", further analyze their historical login behaviors to determine whether there is a possibility of misjudgment, that is: if an IP address segment's main login behavior shows successful logins and the login failure rate remains below a relatively low threshold within a specific past time period, for example, within the past 7 days, successful logins are dominant and the failure rate is less than 5%, then remove this IP address segment from the malicious login behavior set.

[0184] ③ Exclusion of misjudgments based on scenarios: In order to balance the normal business requirements in different time periods, it is necessary to implement a dynamic adjustment strategy for the judgment threshold of malicious login behaviors, and accordingly remove some misjudged malicious IP addresses from the malicious login behavior set. Specifically, during regular working hours (such as 9:00 to 18:00), the judgment criteria will be appropriately relaxed to reduce interference with normal business activities.

[0185] Among them, the standard formulation for normal business requirements fully considers the geographical location information (ASN) of IP address segments, and different judgment criteria are adopted for IP address segments originating from different regions. For example, for the IP address segments in the core business area of an enterprise, the judgment threshold will be appropriately relaxed to ensure the smooth progress of business.

[0186] To apply the embodiments of the present application, please refer to Figure 2 , Figure 2 which is the data interaction diagram provided by the embodiments of the present application, showing the relationships between the modules and the data flow mode in this embodiment; among them, the security protection system includes a log collection module, a log processing module, a rule engine module, and a database module; the log collection module includes a containerized log collector; the log processing module includes a log parser, a data format converter, and log storage; the rule engine module includes an IP segment identifier, an attack behavior judge, a false positive eliminator, and a rule updater; the database module includes an IP block list;

[0187] Among them, the specific interaction relationships between the modules are as follows:

[0188] When a user logs in to the email server, the mail service component generates a login log;

[0189] The containerized log collector immediately captures this log information;

[0190] The collected logs are then sent to the log parser for processing;

[0191] The log parser extracts key information from it and passes it to the data format converter;

[0192] The data format converter is responsible for converting the information into a standard format and storing it in the log storage system;

[0193] The IP segment identifier reads data from the log storage and identifies the corresponding IP address segment;

[0194] The attack behavior judge combines these IP address segments with the log data to evaluate whether there is a malicious login attempt;

[0195] The false positive eliminator further screens and eliminates normal IP address segments;

[0196] The rule updater updates the IP block list in the database according to the final analysis conclusion;

[0197] The email server intercepts connection requests from malicious IPs based on the IP block list to ensure the security of the server.

[0198] In this embodiment, the exclusion unit can exclude IP address segments that are known to be normal or trustworthy through the whitelist mechanism, thus avoiding misclassifying them as malicious IPs. Excluding IP address segments that conform to the preset normal behavior and those with a low login failure rate within the preset time period can significantly reduce the number of IP address segments that need to be further analyzed and processed, thereby reducing resource consumption, improving detection efficiency, and further reducing the false positive rate;

[0199] Moreover, traditional technologies ignore the false positive problem, while this embodiment automatically eliminates false positives by distinguishing normal services from potential malicious IP segments, significantly improving the recognition accuracy. Traditional technologies rely on manual update of the rule blacklist, while this embodiment realizes the automated management of protection rules by automatically analyzing logs through a program and updating the IP block list in real time.

[0200] It should be noted that in the second embodiment, Docker (container technology) and Elasticsearch (elastic search engine) are used for log collection and analysis; this embodiment utilizes the Docker containerized deployment and the log analysis ability of Elasticsearch. By optimizing the log analysis and data processing processes, it can reduce the occupation of system resources and ensure the normal operation of the SMTP server in a high-traffic environment.

[0201] Overall, this embodiment has the following beneficial effects:

[0202] The malicious login behavior determination technology of this application can accurately identify IP addresses based on various information in the login logs; through comparative analysis, it can distinguish which IP addresses are malicious and which are legitimate. This accurate identification ability helps to reduce misjudgment and improve the accuracy of protection. By introducing the mechanism of misjudgment exclusion, it can reduce the phenomenon of false bans caused by improper rule settings or normal user behaviors; this ensures that only truly malicious IP address segments will be included in the blacklist, thus avoiding interference and damage to normal users. Once the list of malicious IP address segments is determined, access requests from the specified IP address segments to the SMTP server can be blocked based on this information; this targeted blocking measure can directly and effectively prevent malicious behaviors from occurring, thereby protecting the security of the server. Moreover, this application can continuously adjust and optimize the determination rules and blocking strategies based on real-time data and behavior analysis, so as to better adapt to the changing attack patterns and threat environments;

[0203] In addition, this application uses dynamic IP segment behavior analysis to effectively defend against brute force attacks on SMTP servers, especially distributed attacks. By comprehensively analyzing login attempts and IP segments, malicious attacks can be accurately identified, which goes beyond traditional single-IP detection. By intelligently comparing normal and potentially malicious IP segments, false positives can be automatically excluded, improving the protection accuracy. At the same time, it can automate the update of protection rules without manual intervention, quickly respond to new attack patterns, and reduce maintenance costs. Elasticsearch is used to process logs, and its distributed architecture and efficient indexing ensure that massive logs can be processed quickly. Containerized deployment optimizes the system deployment process and expansion ability, thus ensuring the security, stability, and efficiency of SMTP server protection.

[0204] Embodiment 3:

[0205] The embodiment of this application provides a computer-readable storage medium, which includes a stored computer program. When the computer program runs, it controls the device where the computer-readable storage medium is located to execute the described method for protecting an SMTP server based on dynamic log analysis.

[0206] Among them, for the described method for protecting an SMTP server based on dynamic log analysis, if it is implemented in the form of a software functional unit and used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, to implement all or part of the processes in the above embodiment methods of the present invention, it can also be completed by instructing relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by a processor, the steps of the above various method embodiments can be implemented. Among them, the computer program includes computer program code, and the computer program code can be in the form of source code, object code, executable file, or some intermediate form, etc. The computer-readable medium can include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), electrical carrier signal, telecommunication signal, and software distribution medium, etc.

[0207] The above are the preferred embodiments of the present invention. It should be noted that for those of ordinary skill in the art in this technical field, without departing from the principle of the present invention, several improvements and refinements can be made, and these improvements and refinements are also regarded as the protection scope of the present invention.

Claims

1. A method for protecting an SMTP server based on dynamic log analysis, characterized in that, Including: Obtain the login logs of the SMTP server; Determine malicious login behaviors and exclude misjudgments for the IP address segments in the login logs to obtain a list of malicious IP address segments, and block access requests from specified IP address segments to the SMTP server according to the list of malicious IP address segments.

2. The method for protecting an SMTP server based on dynamic log analysis according to claim 1, wherein, Determine malicious login behaviors and exclude misjudgments for the IP address segments in the login logs to obtain a list of malicious IP address segments, specifically: Extract information and convert data from the login logs to obtain a first data set; Perform multi-dimensional data screening on the first data set to obtain a set of malicious login behaviors; wherein, the multi-dimensional data screening includes time window dynamic score screening and login failure rate threshold screening; Exclude IP address segments that conform to preset normal behaviors from the set of malicious login behaviors to obtain the list of malicious IP address segments composed of several malicious IP address segments.

3. The method for protecting an SMTP server based on dynamic log analysis according to claim 2, wherein, Perform multi-dimensional data screening on the first data set to obtain a set of malicious login behaviors, specifically: In the first data set, define the IP address segments that meet any condition in the condition set as malicious IP address segments to obtain the set of malicious login behaviors composed of several malicious IP address segments; Wherein, the condition set includes a first condition, a second condition, a third condition, and a fourth condition.

4. The method for protecting an SMTP server based on dynamic log analysis according to claim 3, characterized in that, The first condition, specifically: According to the number of successful logins and the number of failed logins of the IP address segment within a specified time window, calculate the login failure rate for the corresponding time window to obtain the login failure rates within several time windows; Define the IP address segments whose login failure rate exceeds the preset threshold within the preset time window as objects that meet the first condition.

5. The method for protecting an SMTP server based on dynamic log analysis according to claim 3, characterized in that, The second condition, specifically: According to the preset business requirements, assign corresponding weights to different types of login failure reason categories; For each IP address segment and each time window, calculate the weighted total failure score according to the number of occurrences of each login failure reason and the corresponding weight; Define the IP address segments whose weighted total failure score exceeds the preset threshold within the preset time window as objects that meet the second condition.

6. The method for protecting an SMTP server based on dynamic log analysis according to claim 3, wherein, The third condition and the fourth condition, specifically: Define the IP address segments that are marked as IP blacklists by several target services and the number of marked times exceeds the preset threshold as objects that meet the third condition; Define the IP address segments with a reputation score lower than the preset threshold as objects that meet the fourth condition; wherein, the reputation score is obtained by scoring the login behavior of the IP address segment and whether it is marked by the target service.

7. The SMTP server protection method based on dynamic log analysis according to claim 2, wherein Exclude IP address segments that conform to preset normal behaviors from the set of malicious login behaviors to obtain the list of malicious IP address segments composed of several malicious IP address segments, specifically: Exclude IP address segments that conform to preset normal behaviors from the set of malicious login behaviors according to the whitelist, and exclude the IP address segments with a login failure rate lower than the preset threshold within the preset time period from the set of malicious login behaviors to obtain the list of malicious IP address segments composed of several malicious IP address segments.

8. A protection device for an SMTP server based on dynamic log analysis, characterized in that, Including a data module and a protection module; Wherein, the data module is used to obtain the login logs of the SMTP server; The protection module is used to determine malicious login behaviors and exclude misjudgments for the IP address segments in the login log, obtain a list of malicious IP address segments, and block access requests from specified IP address segments to the SMTP server according to the list of malicious IP address segments.

9. The SMTP server protection device based on dynamic log analysis according to claim 8, characterized in that, The protection module includes a data unit, a screening unit, and an exclusion unit; Among them, the data unit is used to extract information and perform data conversion on the login log to obtain a first data set; The screening unit is used to perform multi-dimensional data screening on the first data set to obtain a set of malicious login behaviors; among them, the multi-dimensional data screening includes dynamic scoring screening in a time window and threshold screening of the login failure rate; The exclusion unit is used to exclude IP address segments that meet the preset normal behaviors from the set of malicious login behaviors to obtain the list of malicious IP address segments composed of several malicious IP address segments.

10. The SMTP server protection device based on dynamic log analysis according to claim 9, characterized in that, The screening unit is specifically: In the first data set, an IP address segment that meets any condition in the condition set is defined as a malicious IP address segment, and the set of malicious login behaviors composed of several such malicious IP address segments is obtained; Among them, the condition set includes a first condition, a second condition, a third condition, and a fourth condition.

11. The SMTP server protection device based on dynamic log analysis according to claim 10, characterized in that, The first condition is specifically: According to the number of successful logins and the number of failed logins of an IP address segment within a specified time window, calculate the login failure rate for the corresponding time window to obtain the login failure rates within several time windows; An IP address segment whose login failure rate exceeds the preset threshold within the preset time window is defined as an object that meets the first condition.

12. The SMTP server protection device based on dynamic log analysis according to claim 10, characterized in that, The second condition is specifically: According to the preset business requirements, assign corresponding weights to different types of login failure reason categories; For each IP address segment and each time window, calculate the weighted total failure score according to the number of occurrences of each login failure reason and the corresponding weight; An IP address segment whose weighted total failure score exceeds the preset threshold within the preset time window is defined as an object that meets the second condition.

13. The SMTP server protection device based on dynamic log analysis according to claim 10, characterized in that, The third condition and the fourth condition are specifically: An IP address segment that is marked as an IP blacklist by several target services and the number of marked times exceeds the preset threshold is defined as an object that meets the third condition; An IP address segment whose reputation score is lower than the preset threshold is defined as an object that meets the fourth condition; among them, the reputation score is obtained by scoring the login behavior of the IP address segment and whether it is marked by the target service.

14. The SMTP server protection device based on dynamic log analysis according to claim 9, characterized in that, The exclusion unit is specifically: Exclude IP address segments that meet the preset normal behaviors from the set of malicious login behaviors according to the whitelist, and exclude IP address segments with a login failure rate lower than the preset threshold within the preset time period in the set of malicious login behaviors to obtain the list of malicious IP address segments composed of several malicious IP address segments.

15. A storage medium, characterized in that, A computer program is stored on the storage medium, and the computer program is called and executed by the computer to implement a method for protecting an SMTP server based on dynamic log analysis as described in any one of claims 1 to 7 above.