Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

94 results about "Attack signature" patented technology

Attack signature. A file containing a data sequence used to identify an attack on the network, typically using an operating system or application vulnerability. Such signatures are used by an Intrusion Detection System (IDS) or firewall to flag malicious activity directed at the system.

Information security management system based on network operation and maintenance

The invention belongs to the technical field of network information security, and discloses an information security management system based on network operation and maintenance. The method comprises the following steps: periodically acquiring multi-dimensional traffic data of a network node through a traffic acquisition module, and constructing and labeling a network security situation map by means of an asset labeling module; the authority distribution module automatically adjusts the authority of the abnormal access node by analyzing the node access behavior; the threat detection module analyzes the flow in real time, drives the self-adaptive isolation module to quickly isolate threat nodes according to the generated temporary strategy, and updates the joint defense model for cooperative defense; the attack evolution prediction module performs attack path prediction by extracting attack features and optimizes an isolation strategy accordingly; and information leakage is effectively prevented.
Owner:GUANGZHOU PENGLONGJISUANJI TECH CO LTD

Federal learning poisoning defense method based on time-frequency spectrogram and comparative learning

The invention relates to the technical field of federated learning security, and discloses a federated learning poisoning defense method based on time-frequency spectrogram and comparative learning, which comprises the following steps: receiving model update uploaded by each client, grouping and vectorizing parameters according to model layers, and generating a time-frequency spectrogram by applying short-time Fourier transform to parameter vectors of each layer; based on the time-frequency spectrogram, constructing a positive sample pair through data enhancement, carrying out difficult negative sample mining, and training an encoder by using a contrast loss function to extract an embedded vector with high discriminant power; and performing unsupervised clustering on the embedded vector by using a DBSCAN clustering algorithm, judging the maximum cluster as a benign client, performing final judgment in combination with historical malicious records, and only aggregating model parameters of the benign client to update a global model. According to the invention, high-precision detection of attack features can be realized, and a more universal, more efficient and more practical federal learning poisoning attack defense method is realized.
Owner:SICHUAN UNIV

Unknown attack detection method and system for intelligent network security situation awareness

The invention discloses an unknown attack detection method and system for intelligent network security situation awareness, and the method comprises the steps: obtaining multi-dimensional data of a power grid monitoring system, carrying out the data preprocessing, carrying out the network attack preliminary detection of the multi-dimensional data through a pre-built network security situation awareness framework, and outputting suspected attack data, the method comprises the steps of performing data training on historical attack data through an improved OCN open set classification network, identifying attack features of each known attack type, performing semantic similarity calculation on the attack features and suspected attack data, performing attack feature mapping and clustering on the suspected attack data based on semantic similarity, and obtaining an unknown attack feature clustering result. And according to the unknown attack clustering result, carrying out attack type classification on unknown attacks in the suspected attack data to obtain an unknown attack detection result. The method has the effects of detecting unknown attack means in time, effectively reducing the risk that the power grid system suffers from network attacks and guaranteeing safe and stable operation of the power grid system.
Owner:CHINA DATANG CORPORATION SCIENCE AND TECHNOLOGY GENERAL RESEARCH INSTITUTE +1

Lightweight SDN attack detection method based on multi-scale iterative attention

The invention discloses a lightweight SDN (Software Defined Network) attack detection method based on multi-scale iterative attention, relates to the technical field of network security, and solves the problem that an SDN attack detection method based on deep learning in the prior art is insufficient in feature selection static state and spatial modeling and gives consideration to both lightweight and high precision. The method is based on a feature contribution degree evaluation mechanism, the most critical features for attack discrimination are screened out in real time, redundant information is eliminated, and the calculation burden is reduced. Moreover, the attack feature map is generated through normalization, time window overlapping slicing and multi-channel space coding, so that the perception capability of a complex attack mode is improved. Besides, a multi-scale iteration attention mechanism is embedded in a lightweight network architecture, key features are highlighted and redundant information is suppressed through multi-granularity convolution extraction and iteration weight fusion, and both lightweight and high-precision detection are realized, so that the method is suitable for real-time network environment and edge device deployment.
Owner:ELECTRIC POWER RES INST OF GUANGXI POWER GRID CO LTD

Systems and methods for automatic vulnerability mitigation

Disclosed are systems and methods for detecting a vulnerability across programs of an enterprise system and automatically mitigating the vulnerability. The systems and methods utilize artificial intelligence (“AI”) systems to process data received from a particular network, such as systems data, software data, and software configuration data. The AI systems processes the software data and software configuration data and compares the data to known vulnerabilities stored to a database. The system maps the vulnerabilities to attack signatures. When a vulnerability is identified within the network, the AI systems run classification analysis and categorization analysis to determine the probability a vulnerability is a known vulnerability and the category of software it relates to. The system self-executes a rule that enables the attack signatures to protect against the identified vulnerability by either removing or patching.
Owner:TRUIST BANK

Web application firewall rule generation method and device, equipment and medium

The invention relates to a Web application firewall rule generation method and device, equipment and a medium, and the method comprises the steps: obtaining attack feature description information based on log information, latest vulnerability information and user demand information through a large language model; the log information comprises Web request information sent by the client; the newest vulnerability information represents newest vulnerabilities injected in the Web request information; the user demand information represents Web request information needing to be protected by the Web application firewall; calling a target tool through a model context protocol module; generating a Web application firewall rule based on the attack feature description information through the target tool; the target tool is a tool related to Web application firewall rule generation, and the efficiency and accuracy of Web application firewall rule generation are improved.
Owner:CHINA TELECOM CLOUD TECH CO LTD

Systems and methods for vulnerability smart routing

Disclosed are systems and methods for detecting a vulnerability across programs of an enterprise system and notifying remediation agent. The systems and methods utilize artificial intelligence (“AI”) systems to process data received from a particular network, such as systems, software, and software configuration data. The AI systems processes the software and software configuration data and compares the data to known vulnerabilities stored to a database. The system maps the vulnerabilities to attack signatures. When a vulnerability is identified within the network, the AI systems run classification analysis and categorization analysis to determine the probability a vulnerability is a known vulnerability and the category of software it relates to. The AI systems then runs a remediation agent analysis to determine the proper remediation agent to mitigate the vulnerability. Once a remediation agent is determined, a remediation agent is notified of the vulnerability and mitigates the vulnerability by removing or patching.
Owner:TRUIST BANK

Malicious request interception system based on multi-dimensional behavior analysis and cloud-ground cooperation

The invention provides a malicious request interception system based on multi-dimensional behavior analysis and cloud-ground collaboration, relates to the technical field of network security, and analyzes normal equipment characteristics, a user behavior sequence and a cloud malicious equipment blacklist by collecting TCP / IP protocol stack characteristics and combining dynamic characteristics of the user behavior sequence. First interception is performed according to an analysis structure, deep identification is performed on a user behavior sequence after the first interception based on time sequence analysis and clustering analysis, and second interception is performed according to an identification result, so that the problems that a static rule cannot identify novel attacks and group attack features are difficult to capture are solved; and carrying out content verification on the user behavior sequence after the second interception, and carrying out third interception according to a verification result, thereby realizing dynamic adaptation of a service scene, solving the problem of poor static rule adaptability, carrying out whole system synchronization on all intercepted malicious logs, avoiding cross-node missed interception of malicious requests, and forming a defense iteration closed loop.
Owner:SHENZHEN INTERNET PIONEER TECH CO LTD

Network security intelligent detection method based on big data

The invention relates to the field of data security, in particular to a network security intelligent detection method based on big data, and the method comprises the steps: collecting network flow data, a terminal system call sequence and a user operation behavior log, and carrying out the data fusion processing to generate a unified behavior event flow; selecting a key behavior event based on an information entropy threshold value, performing time alignment through a dynamic time warping algorithm, and constructing a behavior gene map containing a communication association gene, an operation sequence gene and a behavior time sequence gene; a dynamic behavior baseline model is established by using unsupervised learning, and gene mutation detection and alarm are realized by calculating the deviation degree of each gene dimension; the detection performance is evaluated based on the false alarm rate, model parameters are optimized through a negative feedback mechanism, and acknowledged attack features are stored in a sharable threat gene feature library through a positive feedback mechanism. According to the method, the detection accuracy is continuously improved through a closed-loop learning mechanism, and a self-adaptive safety protection system with self-optimization capability is constructed.
Owner:BEIJING JINBO SHUNCHANG NETWORK TECHNOLOGY CO LTD

Network security knowledge graph construction method and system

The invention relates to the technical field of network security, in particular to a network security knowledge graph construction method and system, and the method comprises the following steps: extracting information from original network traffic, logs and threat intelligence, extracting attack features, classifying and storing the attack features in a knowledge base, screening high-risk nodes, judging weak points, generating dynamic keys, and distributing and storing the dynamic keys. The method comprises the following steps of: extracting attack characteristics, carrying out logic classification, constructing a multi-dimensional associated security data system, identifying a threat path and a high-risk node, combining abnormal detection and path complexity comparison, encrypting basic data, verifying and decrypting, adjusting a security policy rule according to an environment, and executing dynamic adjustment of a network security protection policy. According to the method, hidden weak points are accurately judged, a dynamic key generation and distribution mechanism is adopted, encryption consistency and security are improved, distributed encryption exchange and real-time verification are matched, confidentiality and integrity of data transmission and storage are guaranteed, protection self-adaptive adjustment is achieved according to an environment state matching strategy, and response efficiency and flexibility are improved.
Owner:SICHUAN POLICE COLLEGE

Multivariate attack feature recognition method and system based on persistent threat attack

The invention is suitable for the technical field of network security, and provides a multivariate attack feature recognition method and system based on persistent threat attacks, and the method comprises the steps: obtaining a real-time traffic data sequence in a target network environment; performing primary anomaly sensing processing on the real-time traffic data sequence to obtain a suspicious traffic fragment set; executing thinking chain reasoning analysis on the suspicious traffic fragment set, and generating an attack behavior reasoning path comprising multi-stage reasoning steps; performing matching verification on the attack behavior reasoning path and a pre-constructed threat intelligence knowledge base, and determining an attack stage and an attack intention of the persistent threat attack; and generating a multivariate attack feature recognition result according to a matching verification result. According to the method, analysis of advanced persistent threat attack multi-stage features is realized through a thinking chain reasoning mode, and the timeliness and reliability of detection are improved, so that the active protection capability of network security is improved.
Owner:CHINA DATANG CORPORATION SCIENCE AND TECHNOLOGY GENERAL RESEARCH INSTITUTE +1

Intelligent micro-grid network attack detection method and system based on block chain, wavelet transform and support vector machine, medium and processor

PendingCN121441527ACircuit arrangementsKernel methodsSmart microgridAttack
The invention discloses an intelligent micro-grid network attack detection method and system based on a block chain, wavelet transform and a support vector machine, a medium and a processor, and relates to the field of power grid network attack detection. The method aims at solving the problems that normal and attack exception are difficult to distinguish, the missing and false detection rate is high, and data are tampered easily in a traditional method. The method comprises the following steps: collecting and preprocessing DC micro-grid data; decomposing into high and low frequency components through wavelet transform, and extracting amplitude, frequency and energy related characteristic parameters; constructing and training a support vector machine model for real-time attack detection; and after detecting full-process data hash processing, uploading the data to the block chain, and storing evidence based on a PoA consensus mechanism. According to the method, attack features are accurately captured through wavelet transformation, high-accuracy classification is realized in combination with the SVM, the block chain guarantees data credibility, a micro-grid dynamic scene can be quickly responded, and the network security protection capability is improved.
Owner:ELECTRIC POWER RES INST OF GUANGXI POWER GRID CO LTD

Abnormal traffic cooperative detection method and system

The invention discloses an abnormal traffic cooperative detection method and system, and relates to the field of network communication, and the method comprises the steps: carrying out the protocol adaptive recognition and dynamic attack detection at a north-south WAF layer, generating an attack fingerprint, and binding a global session ID; full-link monitoring is carried out on application behaviors on an east-west RASP layer, and context association and threat analysis are realized through a session ID; aggregating WAF and RASP data based on the session ID, constructing an attack feature propagation atlas and evaluating attack chain confidence; when the confidence exceeds a threshold value, the RASP layer extracts attack features and generates a virtual patch rule, and feeds back the attack features and the virtual patch rule to the WAF layer for real-time updating; and finally, collaborative blocking is realized through bidirectional confidence fusion decision of the WAF and the RASP. The problem that in the prior art, detection in the north-south direction and detection in the east-west direction are separated, and a cross-layer attack chain cannot be effectively blocked is solved, and precise and dynamic protection on complex attacks, especially encrypted traffic and transverse penetration is achieved.
Owner:WUHAN CITY VOCATIONAL COLLEGE +2

A method for security threat perception and detection of global network devices

ActiveCN121841825BInternet trafficAttack
This invention discloses a security threat perception and detection method for global network devices. It simultaneously collects three types of data: network traffic, behavior logs, and attack characteristics, forming multi-dimensional factual evidence. The method utilizes a firework algorithm to optimize the deployment of logical monitoring points (feature nodes) in the virtual network and calculates the dynamic intensity of threat propagation at each point, thereby constructing a node-level threat field that quantifies the spatial distribution of threats. Subsequently, peak, mean, and dispersion indicators are extracted, and behavioral load, threat polarization, and cumulative threat indicators are calculated from the raw data, forming a six-dimensional vector. This vector is input into a pre-trained global threat level classification model, outputting a discrete threat level. Finally, based on this level, firewall rules, intrusion detection feature libraries, and other protection strategies are dynamically adjusted to achieve automatic matching of security configuration and threat posture.
Owner:BEIJING SHANGZHANG INFORMATION TECHNOLOGY CO LTD

An AI-based network security alarm accurate identification and grading method

The application belongs to the field of network security operation, and particularly relates to a network security alarm accurate identification and grading method based on AI.The method is connected with multiple types of security systems to collect alarms and context data, generate a unique alarm identifier and an entity identifier set, and construct an alarm entity graph through entity disambiguation alignment;secondly, multi-dimensional deep features such as time sequence self-excitation and topological persistence are extracted, normalized and spliced into feature objects and stored in a feature warehouse;then, corresponding data is obtained through a normal behavior self-supervision and attack technology identification double-track model, and a true alarm probability is calculated through an evidence ratio fusion model;and finally, alarm dynamic grading and differentiated disposal are realized based on attack features and risk budget.The application reduces the alarm false alarm rate, solves the problem of disposal resource mismatch, and enhances the security operation efficiency.
Owner:JIANGSU JUNAN SAFETY INSPECTION CO LTD

Cluster-based recommendation system interaction level member inference attack method, storage medium and computer device

This invention provides a clustering-based method for attacking interaction-level membership in a recommender system. It involves constructing a shadow dataset with a distribution consistent with the training dataset of the target recommender system, and training a shadow recommender model based on it. For users in the shadow dataset, the method obtains the corresponding recommendation list provided by the shadow recommender model. The recommendation list is then clustered to generate user representation vectors representing users' multiple interests. Furthermore, based on the user representation vectors, the vector representations of candidate items, and the similarity between candidate items and each cluster, an attack feature vector is constructed. This attack feature vector is then used to train the attack model. The interaction to be audited in the target recommender system is input into the trained attack model to determine whether the interaction belongs to the training data of the target recommender system. Thus, this invention mitigates ranking bias by constructing multi-interest user representations through clustering, achieving accurate and reliable auditing of the use of single interaction data in the recommender system.
Owner:INST OF COMPUTING TECH CHINESE ACAD OF SCI

A method and system for predicting cybersecurity situation based on artificial intelligence

This invention relates to the field of network security technology and discloses a network security situation prediction method and system based on artificial intelligence, comprising the following steps: embedding controllable Trojan data into user-facing software by uploading network data; collecting hardware information data of the software and software status data of the user-facing software based on a data acquisition module; extracting feature vectors from the hardware information data and software status data; and then having a third party evaluate the security coefficient of the controllable Trojan data. This invention, by proactively embedding a controllable, fingerprint-hidden authorized Trojan in a real software environment for attack and defense drills, overturns the passive mode of traditional security detection that relies on historical attack characteristics or static rule bases. This enables proactive perception and discovery of attack clues for unknown threats and advanced persistent threats, greatly improving the system's predictability of potential risks.
Owner:SHANDONG DINGXIA INTELLIGENT TECH CO LTD +1

Threat intelligence guided confrontation knowledge distillation detection method

The invention discloses an adversarial knowledge distillation detection method guided by threat intelligence, relates to the technical field of network security protection, and solves the problems of low detection accuracy and defense lagging of novel network attacks in the prior art. According to the embodiment of the invention, the alarm frequency is converted into the multi-scale Grubrum angle field image features, attack features under different time scales can be captured, a cross-time-dimension complex attack chain and hidden association can be visually recognized, the missing report rate is reduced, and the detection capability of unknown variant attacks and low-frequency slow attacks is improved. Under the condition that novel threat intelligence is obtained, a targeted first training sample is generated in combination with a multi-scale Gramer angle field image, and first adversarial training of a student model is quickly triggered, so that the detection capability of novel attacks is accurately improved, and the problem of defense lag is improved.
Owner:GUANGXI POWER GRID CORP

Intelligent waf attack traffic discrimination method, system, device and medium based on large model MoE

PendingCN122394831AWeb applicationAttack
The application discloses an intelligent WAF attack flow discrimination method, system, device and medium based on a large model MoE, belongs to the technical field of network security and artificial intelligence, and aims to solve the technical problem that an existing Web Application Firewall mainly relies on rule matching or a single model mode in an attack flow discrimination process, and it is difficult to effectively cope with diversified attack types, significant attack feature differences and dynamic business environment changes. The technical scheme is as follows: collecting Web access flow: collecting access request flow entering a Web application from a Web Application Firewall or a network environment where the Web Application Firewall is located through flow mirroring, bypass listening, log collection or interface calling; analyzing and preprocessing the access flow: analyzing and preprocessing the access request flow to generate structured request data; constructing a flow feature vector; discriminating attacks based on a large model of an MOE architecture; outputting an attack flow discrimination result; and executing a WAF protection strategy.
Owner:SHANDONG LANGCHAO YUNTOU INFORMATION TECH CO LTD +1

Attack feature acquisition method, electronic device, storage medium and computer program product

The invention relates to the technical field of communication security, and provides an attack feature acquisition method, electronic equipment, a storage medium and a computer program product. The method comprises the following steps: acquiring each attack sample; performing semantic analysis on any attack sample to obtain a semantic unit sequence of the attack sample; according to the occurrence frequency of each semantic unit sequence in each attack sample, determining each target semantic sequence from each semantic unit sequence; performing frequent pattern mining on each target semantic sequence to obtain at least one frequent semantic sequence, and generating attack features according to each frequent semantic sequence; wherein the semantic sequence comprises at least one semantic unit. According to the attack feature acquisition method provided by the embodiment of the invention, the reliability of the acquired attack features can be improved.
Owner:BEIJING TOPSEC NETWORK SECURITY TECH +2

Data security management method and device, equipment, storage medium and program product

The application provides a data security management and control method, device, equipment, storage medium and program product. The method comprises the following steps: obtaining network flow data to be detected in a target detection scene and a training sample library of the target detection scene, wherein the training sample library comprises sample feature data and sample attack types of a plurality of training samples; preprocessing the network flow data to obtain first feature data of the network flow data; inputting the first feature data into a pre-trained first model to obtain second feature data output by the first model, wherein the first model is used for extracting attack features in the first feature data through a convolution operation to generate the second feature data; calculating a first Euclidean distance between the second feature data and the sample feature data of the training sample; performing type matching on the sample attack types of the training sample and the first Euclidean distance to determine a target attack type of the network flow data. The application has high detection accuracy for network attacks.
Owner:中国移动通信集团江西有限公司 +1

A deep learning-based DDoS attack detection method

This invention belongs to the field of network security technology and discloses a deep learning-based DDoS attack detection method, including S1, data preprocessing, which performs data cleaning, noise reduction, and format standardization on the acquired network traffic data stream to ensure that the data is suitable for subsequent processing; S2, feature selection, which transmits the preprocessed network traffic data to a feature selection module and uses a selective deep autoencoder to extract potential attack features from the network traffic data; S3, attack detection, which transmits the extracted network traffic data features to a DDoS attack detection module and uses a CNN-Self-Attention model to detect whether the network traffic data is DDoS attack traffic and identify its attack type. This invention can extract important characteristics from complex network traffic data, improve detection accuracy, and achieve high accuracy results, making it suitable for current DDoS attack detection systems.
Owner:XIDIAN UNIV HANGZHOU RES INST +1

A network attack detection method, system, device and storage medium

This application provides a network attack detection method, system, device, and storage medium. The method includes: acquiring network data; constructing a first prompt word based on the network data, including model roles, network data, model tasks, and model output format; inputting the first prompt word into a first model to perform preliminary detection on the network data, outputting preliminary results, and preliminarily determining whether the network data has attack characteristics and its attack type; marking network data with attack characteristics in the preliminary results as target data; retrieving related knowledge matching the attack type of the target data from a knowledge base; constructing a second prompt word based on the related knowledge, including a set of historical attack cases, location information of historical network attack characteristics, historical network attack detection rules, and model output format; inputting the second prompt word and the target data into a second model to perform deep detection on the target data, outputting deep results, and determining whether the target data has attack characteristics and its attack type.
Owner:HANGZHOU DPTECH TECH

Detection device, detection method, and detection program

A detection device includes processing circuitry configured to acquire user generated content generated in each service in a predetermined period, generate a search query using words appearing in the user generated content for each service, collect the user generated content generated in a plurality of services using the generated search query, calculate a feature amount of the collected user generated content of a predetermined service, perform learning using the feature amount of the user generated content generated by a normal user and a feature amount of content generated by a malicious user, determine whether the user generated content is generated by a malicious user based on a learned model, and access an entrance URL described in the user generated content and output a feature of an attack of the user generated content as threat information when the user generated content is determined to be generated by a malicious user.
Owner:NT T INC

Attack detection method, electronic equipment and computer program product

PendingCN121887371AReduce the false positive rate of attack detectionReduce the likelihood of false negativesSecuring communicationFeature setAttack
The embodiment of the invention is suitable for the technical field of network security, and provides an attack detection method, electronic equipment and a computer program product, and the method comprises the steps: obtaining transaction operation data of a block chain; constructing a candidate attack sequence based on a sandwich attack feature set and the transaction operation data; the candidate attack sequence comprises three exchange operations; according to the embodiment of the invention, the missing report rate and the false report rate of sandwich attack detection can be reduced, and the credibility and the applicability of sandwich detection are improved.
Owner:HANGZHOU HIGH-TECH ZONE (BINJIANG) INSTITUTE OF BLOCKCHAIN & DATA SECURITY

End-management-cloud dynamic defense topology construction method

PendingCN121984692AImprove protection adaptabilityRealize collaborative linkageBiological modelsSecuring communicationAttackSecurity domain
The invention discloses an end-management-cloud dynamic defense topology construction method, relates to the technical field of network security protection, and solves the problem of insufficient protection strength and adaptability to network attacks in the prior art. According to the embodiment of the invention, the gray point agents are deployed at different levels of the system respectively, and the information is uniformly reported to the central arrangement engine of the cloud for uniform processing when the abnormal behavior is detected, so that collaborative linkage of multiple gray point agents is realized; through a reinforcement learning model, different strategies are adopted based on attack feature vectors of abnormal behaviors, and the protection adaptability to network attacks is improved; attacks are introduced into the controllable sandbox through an isolation strategy, so that local microscopic hemostasis can be realized; attack fingerprints are actively collected through a trapping strategy, and the threat intelligence quality can be improved; the service module can operate independently in combination with security domain isolation, the system toughness is guaranteed, and the protection strength is improved.
Owner:GUANGXI POWER GRID CORP

Adaptive network defense and topology reconstruction system based on attack feature learning

The invention discloses a self-adaptive network defense and topology reconstruction system based on attack feature learning, and the system comprises a data collection and preprocessing module which is used for collecting network state data and attack information in real time, and carrying out the preprocessing of the collected data; the attack feature embedding module is used for processing the preprocessed network state data by adopting a time sequence diagram neural network so as to automatically extract time sequence features in the network attack and identify an attack mode; the structural feature embedding module is used for learning topological structural features of the network based on the graph neural network; the deep reinforcement learning module is used for generating a network topology reconstruction strategy by adopting a Markov decision process according to the attack mode and the topological structure characteristics; and the network topology reconstruction module is used for executing a network topology reconstruction strategy and carrying out dynamic addition, deletion or reconnection operation on network nodes and edges. According to the method, a self-adaptive defense solution can be provided in the face of compound and multi-modal attacks, and the robustness and the survival rate of the network are improved.
Owner:BEIJING UNIV OF POSTS & TELECOMM

Network attack detection method, device, equipment, storage medium and program product

PendingCN122457295AAttackNetwork attack
The application discloses a network attack detection method, device, equipment, storage medium and program product, and belongs to the technical field of network security. The method comprises the following steps: in response to a network event being a new network attack event, a plurality of attack characteristics are obtained by analyzing the new network attack event; a target attack event is determined according to the similarity between a pre-stored attack event and the plurality of attack characteristics; a defense processing result is obtained by performing defense processing on the new network attack event according to a defense strategy of the target attack event; and an alarm level of the new network attack event is determined according to the defense processing result. In this way, the new network attack event can be adaptively defended, the occurrence of non-critical alarms can be reduced, and the processing efficiency of the new network attack event can be improved.
Owner:CHINA MOBILE GRP BEIJING +1

An abnormal traffic cooperative detection method and system

The application discloses an abnormal flow cooperative detection method and system, relates to the field of network communication, and comprises the following steps: protocol adaptive identification and dynamic attack detection are carried out on a north-south WAF layer, attack fingerprints are generated, and global session IDs are bound; the application behavior is monitored in a whole link on an east-west RASP layer, context association and threat analysis are realized through the session IDs; WAF and RASP data are aggregated based on the session IDs, an attack feature propagation graph is constructed, and attack chain confidence is evaluated; when the confidence exceeds a threshold value, attack features are extracted by the RASP layer, virtual patch rules are generated, and feedback is fed back to the WAF layer for real-time updating; finally, bidirectional confidence fusion decision is realized through the WAF and the RASP, and cooperative blocking is realized. The application solves the problem that the north-south and east-west detection are split in the prior art, and cross-layer attack chains cannot be effectively blocked, realizes accurate and dynamic protection on complex attacks, especially encrypted flow and horizontal penetration.
Owner:WUHAN CITY VOCATIONAL COLLEGE +2

Firewall rule updating method and apparatus, computer device, and storage medium

This application relates to the field of network security technology, and in particular to a firewall rule update method, apparatus, computer device, and storage medium. The method includes: acquiring a target attack sample corresponding to a current firewall rule; if the target attack sample contains a preset attack behavior, determining attack feature information in the target attack sample; determining a new firewall rule corresponding to the target attack sample based on the attack feature information and a rule generation strategy corresponding to the preset attack behavior; and updating the current firewall rule according to the new firewall rule. This application can improve the efficiency of firewall rule updates.
Owner:CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1