A network attack detection and tracing method based on multi-source data
CN122226441APending Publication Date: 2026-06-16BEIJING BOYOTOD TECH CO LTD
View PDF 0 Cites 0 Cited by
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- BEIJING BOYOTOD TECH CO LTD
- Filing Date
- 2026-04-02
- Publication Date
- 2026-06-16
Smart Images

Figure CN122226441A_ABST
Abstract
The application belongs to the technical field of network security, and discloses a network attack detection and tracing method based on multi-source data; by acquiring network flow data, terminal behavior data, identity authentication data and other security data, behavior feature sampling sequences are extracted from each data source and entropy gradient analysis is carried out, behavior mutation anchor points are identified, and a multi-granularity behavior feature description model is constructed. A heterogeneous association graph containing network entities, user entities, process entities and file entities is constructed from entity relationship records, and an associated abnormal offset is calculated through neighborhood attention aggregation. The multi-granularity behavior features and the associated abnormal offset are jointly scored to generate entity abnormal confidence, and a directed time sequence path is traced back for entities exceeding the threshold, and the optimal candidate path is selected as the attack tracing link through time interval consistency analysis. The application realizes a full-link technology closed loop from attack detection to tracing, and improves the recognition ability and tracing accuracy for complex attacks.
Need to check novelty before this filing date? Find Prior Art