CN105306436B - 一种异常流量检测方法 - Google Patents
一种异常流量检测方法 Download PDFInfo
- Publication number
- CN105306436B CN105306436B CN201510591310.XA CN201510591310A CN105306436B CN 105306436 B CN105306436 B CN 105306436B CN 201510591310 A CN201510591310 A CN 201510591310A CN 105306436 B CN105306436 B CN 105306436B
- Authority
- CN
- China
- Prior art keywords
- message
- array
- information
- sequence
- hash
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Expired - Fee Related
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1408—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
- H04L63/1425—Traffic logging, e.g. anomaly detection
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1408—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
- H04L63/1416—Event detection, e.g. attack signature detection
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
- Information Retrieval, Db Structures And Fs Structures Therefor (AREA)
Abstract
Description
Claims (4)
Priority Applications (3)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201510591310.XA CN105306436B (zh) | 2015-09-16 | 2015-09-16 | 一种异常流量检测方法 |
| JP2016179548A JP6071026B1 (ja) | 2015-09-16 | 2016-09-14 | 異常フロー検知方法 |
| US15/267,253 US10505958B2 (en) | 2015-09-16 | 2016-09-16 | Method for detecting abnormal traffic |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201510591310.XA CN105306436B (zh) | 2015-09-16 | 2015-09-16 | 一种异常流量检测方法 |
Publications (2)
| Publication Number | Publication Date |
|---|---|
| CN105306436A CN105306436A (zh) | 2016-02-03 |
| CN105306436B true CN105306436B (zh) | 2016-08-24 |
Family
ID=55203191
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| CN201510591310.XA Expired - Fee Related CN105306436B (zh) | 2015-09-16 | 2015-09-16 | 一种异常流量检测方法 |
Country Status (3)
| Country | Link |
|---|---|
| US (1) | US10505958B2 (zh) |
| JP (1) | JP6071026B1 (zh) |
| CN (1) | CN105306436B (zh) |
Families Citing this family (16)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN105721494B (zh) * | 2016-03-25 | 2019-04-19 | 中国互联网络信息中心 | 一种异常流量攻击检测处置的方法和装置 |
| CN105959300B (zh) * | 2016-06-24 | 2019-09-17 | 杭州迪普科技股份有限公司 | 一种DDoS攻击防护的方法及装置 |
| CN107770113A (zh) * | 2016-08-15 | 2018-03-06 | 台山市金讯互联网络科技有限公司 | 一种精确确定攻击特征的洪水攻击检测方法 |
| CN106330951B (zh) * | 2016-09-14 | 2019-11-19 | 北京神州绿盟信息安全科技股份有限公司 | 一种网络防护方法、装置和系统 |
| CN106685693A (zh) * | 2016-11-18 | 2017-05-17 | 汉柏科技有限公司 | 一种网络异常检测方法、系统及网络设备 |
| US10116671B1 (en) | 2017-09-28 | 2018-10-30 | International Business Machines Corporation | Distributed denial-of-service attack detection based on shared network flow information |
| US11563756B2 (en) | 2020-04-15 | 2023-01-24 | Crowdstrike, Inc. | Distributed digital security system |
| US11711379B2 (en) * | 2020-04-15 | 2023-07-25 | Crowdstrike, Inc. | Distributed digital security system |
| US11861019B2 (en) | 2020-04-15 | 2024-01-02 | Crowdstrike, Inc. | Distributed digital security system |
| US11616790B2 (en) | 2020-04-15 | 2023-03-28 | Crowdstrike, Inc. | Distributed digital security system |
| US11645397B2 (en) | 2020-04-15 | 2023-05-09 | Crowd Strike, Inc. | Distributed digital security system |
| CN112367322B (zh) * | 2020-11-10 | 2022-09-30 | 西安热工研究院有限公司 | 一种基于冒泡排序法的电站工控系统异常流量识别方法 |
| US11836137B2 (en) | 2021-05-19 | 2023-12-05 | Crowdstrike, Inc. | Real-time streaming graph queries |
| CN115694984A (zh) * | 2022-10-31 | 2023-02-03 | 北京威努特技术有限公司 | 一种风暴检测及阻断的方法及系统 |
| CN115766201B (zh) * | 2022-11-11 | 2023-07-18 | 北京哈工信息产业股份有限公司 | 一种大量ip地址快速封禁的解决方法 |
| CN115664869B (zh) * | 2022-12-28 | 2023-05-16 | 北京六方云信息技术有限公司 | 入侵防御系统误识别处理方法、设备以及存储介质 |
Family Cites Families (26)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US6609205B1 (en) * | 1999-03-18 | 2003-08-19 | Cisco Technology, Inc. | Network intrusion detection signature analysis using decision graphs |
| US7702806B2 (en) * | 2000-09-07 | 2010-04-20 | Riverbed Technology, Inc. | Statistics collection for network traffic |
| EP1209861A1 (en) * | 2000-11-22 | 2002-05-29 | Telefonaktiebolaget L M Ericsson (Publ) | Monitoring traffic in packet networks |
| US20020133586A1 (en) * | 2001-01-16 | 2002-09-19 | Carter Shanklin | Method and device for monitoring data traffic and preventing unauthorized access to a network |
| US7114182B2 (en) * | 2002-05-31 | 2006-09-26 | Alcatel Canada Inc. | Statistical methods for detecting TCP SYN flood attacks |
| US7426634B2 (en) * | 2003-04-22 | 2008-09-16 | Intruguard Devices, Inc. | Method and apparatus for rate based denial of service attack detection and prevention |
| US7478156B1 (en) * | 2003-09-25 | 2009-01-13 | Juniper Networks, Inc. | Network traffic monitoring and reporting using heap-ordered packet flow representation |
| JP4743901B2 (ja) * | 2004-07-22 | 2011-08-10 | インターナショナル・ビジネス・マシーンズ・コーポレーション | ネットワーク上での不正なスキャンニングを検出するための方法、システムおよびコンピュータ・プログラム |
| US7669241B2 (en) * | 2004-09-30 | 2010-02-23 | Alcatel-Lucent Usa Inc. | Streaming algorithms for robust, real-time detection of DDoS attacks |
| JP4170301B2 (ja) * | 2005-02-23 | 2008-10-22 | 日本電信電話株式会社 | DoS攻撃検出方法、DoS攻撃検出システム、およびDoS攻撃検出プログラム |
| US20070255861A1 (en) * | 2006-04-27 | 2007-11-01 | Kain Michael T | System and method for providing dynamic network firewall with default deny |
| CN101383694A (zh) * | 2007-09-03 | 2009-03-11 | 电子科技大学 | 基于数据挖掘技术的拒绝服务攻击防御方法和系统 |
| JP4667437B2 (ja) * | 2007-10-02 | 2011-04-13 | 日本電信電話株式会社 | 異常トラフィック検知装置、異常トラフィック検知方法および異常トラフィック検知プログラム |
| CN101150581A (zh) * | 2007-10-19 | 2008-03-26 | 华为技术有限公司 | 分布式拒绝服务攻击检测方法及装置 |
| US8452761B2 (en) * | 2007-10-24 | 2013-05-28 | International Business Machines Corporation | Apparatus for and method of implementing system log message ranking via system behavior analysis |
| US8681628B2 (en) * | 2008-09-30 | 2014-03-25 | The Chinese University Of Hong Kong | Systems and methods for determining top spreaders |
| US7953092B2 (en) * | 2009-04-08 | 2011-05-31 | Ixia | Traffic receiver using parallel capture engines |
| US9112771B2 (en) * | 2009-02-06 | 2015-08-18 | The Chinese University Of Hong Kong | System and method for catching top hosts |
| KR101109669B1 (ko) * | 2010-04-28 | 2012-02-08 | 한국전자통신연구원 | 좀비 식별을 위한 가상 서버 및 방법과, 가상 서버에 기반하여 좀비 정보를 통합 관리하기 위한 싱크홀 서버 및 방법 |
| US9313224B1 (en) * | 2010-09-30 | 2016-04-12 | Google Inc. | Connectivity protector |
| KR101574193B1 (ko) * | 2010-12-13 | 2015-12-11 | 한국전자통신연구원 | 분산 서비스 거부 공격 탐지 및 방어 장치 및 방법 |
| NL2007180C2 (en) | 2011-07-26 | 2013-01-29 | Security Matters B V | Method and system for classifying a protocol message in a data communication network. |
| KR101391781B1 (ko) * | 2012-08-07 | 2014-05-07 | 한국전자통신연구원 | 웹 트랜잭션 밀집도 기반 에이치티티피 봇넷 탐지 장치 및 방법 |
| US9020954B2 (en) * | 2012-09-28 | 2015-04-28 | International Business Machines Corporation | Ranking supervised hashing |
| CN104202336A (zh) * | 2014-09-22 | 2014-12-10 | 浪潮电子信息产业股份有限公司 | 一种基于信息熵的DDoS攻击检测方法 |
| US9838354B1 (en) * | 2015-06-26 | 2017-12-05 | Juniper Networks, Inc. | Predicting firewall rule ranking value |
-
2015
- 2015-09-16 CN CN201510591310.XA patent/CN105306436B/zh not_active Expired - Fee Related
-
2016
- 2016-09-14 JP JP2016179548A patent/JP6071026B1/ja not_active Expired - Fee Related
- 2016-09-16 US US15/267,253 patent/US10505958B2/en not_active Expired - Fee Related
Also Published As
| Publication number | Publication date |
|---|---|
| CN105306436A (zh) | 2016-02-03 |
| US20170078316A1 (en) | 2017-03-16 |
| JP2017059232A (ja) | 2017-03-23 |
| US10505958B2 (en) | 2019-12-10 |
| JP6071026B1 (ja) | 2017-02-01 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| CN105306436B (zh) | 一种异常流量检测方法 | |
| EP3905622B1 (en) | Botnet detection method and system, and storage medium | |
| US11057404B2 (en) | Method and apparatus for defending against DNS attack, and storage medium | |
| Binkley et al. | An algorithm for anomaly-based botnet detection. | |
| AU2019396129B2 (en) | Apparatus and process for monitoring network behaviour of internet-of-things (IoT) devices | |
| CN105049291B (zh) | 一种检测网络流量异常的方法 | |
| US10666672B2 (en) | Collecting domain name system traffic | |
| US10439926B2 (en) | Network analysis | |
| CN106534068B (zh) | 一种ddos防御系统中清洗伪造源ip的方法和装置 | |
| US20050278779A1 (en) | System and method for identifying the source of a denial-of-service attack | |
| CN106357660B (zh) | 一种ddos防御系统中检测伪造源ip的方法和装置 | |
| CN108701187A (zh) | 混合硬件软件分布式威胁分析 | |
| CN103561048A (zh) | 一种确定tcp端口扫描的方法及装置 | |
| US10291632B2 (en) | Filtering of metadata signatures | |
| CN109255237B (zh) | 安全事件关联分析方法及装置 | |
| CN104836702A (zh) | 一种大流量环境下主机网络异常行为检测及分类方法 | |
| JP4626811B2 (ja) | ポートホッピング検出システム、ポートホッピング検出装置、ポートホッピング検出方法、及びプログラム | |
| CN106330964A (zh) | 一种网络入侵探测与主动防御联动控制装置 | |
| CN111786857B (zh) | 基于分布式的网络资产主动探测方法及系统 | |
| US20150372918A1 (en) | System and method for providing congestion notification in layer 3 networks | |
| CN109150859B (zh) | 一种基于网络流量流向相似性的僵尸网络检测方法 | |
| CN105282152B (zh) | 一种异常流量检测的方法 | |
| CN112671759A (zh) | 基于多维度分析的dns隧道检测方法和装置 | |
| CN113676475A (zh) | 一种基于XGBoost的端口扫描恶意流量的检测方法 | |
| JP2010250607A (ja) | 不正アクセス解析システム、不正アクセス解析方法、および不正アクセス解析プログラム |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| C06 | Publication | ||
| PB01 | Publication | ||
| C10 | Entry into substantive examination | ||
| SE01 | Entry into force of request for substantive examination | ||
| CB02 | Change of applicant information |
Address after: 705-708, room two, No. 121, north south of the Five Ridges Avenue, Chancheng District, Guangdong, Foshan, 528000 Applicant after: GUANGDONG EFLYCLOUD COMPUTING Co.,Ltd. Address before: Chancheng District of Guangdong city of Foshan province south of the Five Ridges 528000 Avenue North 121 East International A District Office 7-8 Applicant before: Guangdong Ruijiang Technology Co.,Ltd. |
|
| COR | Change of bibliographic data | ||
| C14 | Grant of patent or utility model | ||
| GR01 | Patent grant | ||
| EE01 | Entry into force of recordation of patent licensing contract |
Application publication date: 20160203 Assignee: Guangdong Zhijiang Network Co.,Ltd. Assignor: GUANGDONG EFLYCLOUD COMPUTING Co.,Ltd. Contract record no.: 2016440000254 Denomination of invention: Abnormal traffic detection method Granted publication date: 20160824 License type: Common License Record date: 20161226 |
|
| LICC | Enforcement, change and cancellation of record of contracts on the licence for exploitation of a patent or utility model | ||
| CF01 | Termination of patent right due to non-payment of annual fee | ||
| CF01 | Termination of patent right due to non-payment of annual fee |
Granted publication date: 20160824 |