Method and device for detecting threat attacks based on behavior pattern analysis

By constructing a data flow and threat attack chain model for matching, advanced persistent threat attacks in the network are detected, solving the problem of insufficient detection capabilities in existing technologies and achieving efficient and accurate threat attack detection.

CN122419804APending Publication Date: 2026-07-17COMP NETWORK INFORMATION CENT CHINESE ACADEMY OF SCI
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
COMP NETWORK INFORMATION CENT CHINESE ACADEMY OF SCI
Filing Date
2025-01-16
Publication Date
2026-07-17

AI Technical Summary

Technical Problem

Existing attack detection methods are ineffective at detecting advanced persistent threat attacks that last for a long time, and are easily bypassed by attackers, lacking adaptability and robustness.

Method used

By extracting the five-tuple information from network data packets, a data flow is constructed and matched with the behavioral stages in the threat attack chain model. Combined with data packet size, communication frequency, and pattern characteristics, threat attack detection is performed, and threat attack alerts are output.

Benefits of technology

It improves the detection recall rate for advanced persistent threat attacks, reduces the false positive rate, has adaptive environmental robustness, can detect unknown attacks, and is suitable for large-scale network environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122419804A_ABST
    Figure CN122419804A_ABST
Patent Text Reader

Abstract

本发明实施例公开了一种基于行为模式分析的威胁攻击检测方法及装置,涉及互联网数据分析技术领域。本发明的方法包括:提取网络中数据包的五元组信息,所述五元组信息包括源IP地址、目的IP地址、源端口号、目的端口号及协议号;获取与所述五元组信息相同的网络中的其他数据包,构成数据流;基于所述数据流中包含的数据包大小、通信频率及通信模式特点,依次与威胁攻击链模型中的各个行为阶段分别进行匹配计算;响应于匹配计算结果为存在威胁攻击,输出威胁攻击警报。本发明能够有效地对实际网络环境进行攻击检测。
Need to check novelty before this filing date? Find Prior Art