A network attack detection and tracing method based on multi-source data

CN122226441APending Publication Date: 2026-06-16BEIJING BOYOTOD TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
BEIJING BOYOTOD TECH CO LTD
Filing Date
2026-04-02
Publication Date
2026-06-16

Smart Images

  • Figure CN122226441A_ABST
    Figure CN122226441A_ABST
Patent Text Reader

Abstract

The application belongs to the technical field of network security, and discloses a network attack detection and tracing method based on multi-source data; by acquiring network flow data, terminal behavior data, identity authentication data and other security data, behavior feature sampling sequences are extracted from each data source and entropy gradient analysis is carried out, behavior mutation anchor points are identified, and a multi-granularity behavior feature description model is constructed. A heterogeneous association graph containing network entities, user entities, process entities and file entities is constructed from entity relationship records, and an associated abnormal offset is calculated through neighborhood attention aggregation. The multi-granularity behavior features and the associated abnormal offset are jointly scored to generate entity abnormal confidence, and a directed time sequence path is traced back for entities exceeding the threshold, and the optimal candidate path is selected as the attack tracing link through time interval consistency analysis. The application realizes a full-link technology closed loop from attack detection to tracing, and improves the recognition ability and tracing accuracy for complex attacks.
Need to check novelty before this filing date? Find Prior Art