Method and device for detecting threat attacks based on behavior pattern analysis
By constructing a data flow and threat attack chain model for matching, advanced persistent threat attacks in the network are detected, solving the problem of insufficient detection capabilities in existing technologies and achieving efficient and accurate threat attack detection.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- COMP NETWORK INFORMATION CENT CHINESE ACADEMY OF SCI
- Filing Date
- 2025-01-16
- Publication Date
- 2026-07-17
AI Technical Summary
Existing attack detection methods are ineffective at detecting advanced persistent threat attacks that last for a long time, and are easily bypassed by attackers, lacking adaptability and robustness.
By extracting the five-tuple information from network data packets, a data flow is constructed and matched with the behavioral stages in the threat attack chain model. Combined with data packet size, communication frequency, and pattern characteristics, threat attack detection is performed, and threat attack alerts are output.
It improves the detection recall rate for advanced persistent threat attacks, reduces the false positive rate, has adaptive environmental robustness, can detect unknown attacks, and is suitable for large-scale network environments.
Smart Images

Figure CN122419804A_ABST