CN111010409B - 加密攻击网络流量检测方法 - Google Patents
加密攻击网络流量检测方法 Download PDFInfo
- Publication number
- CN111010409B CN111010409B CN202010013135.7A CN202010013135A CN111010409B CN 111010409 B CN111010409 B CN 111010409B CN 202010013135 A CN202010013135 A CN 202010013135A CN 111010409 B CN111010409 B CN 111010409B
- Authority
- CN
- China
- Prior art keywords
- traffic
- server
- encrypted
- address
- encrypted traffic
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Active
Links
- 238000001514 detection method Methods 0.000 title claims description 33
- 230000002159 abnormal effect Effects 0.000 claims abstract description 63
- 230000006399 behavior Effects 0.000 claims description 39
- 238000004891 communication Methods 0.000 claims description 16
- 238000011144 upstream manufacturing Methods 0.000 claims description 15
- 230000005856 abnormality Effects 0.000 claims description 14
- 230000000717 retained effect Effects 0.000 claims description 7
- 238000000034 method Methods 0.000 abstract description 24
- 230000006870 function Effects 0.000 abstract description 2
- 238000010586 diagram Methods 0.000 description 11
- 230000002547 anomalous effect Effects 0.000 description 2
- 238000010801 machine learning Methods 0.000 description 2
- 206010000117 Abnormal behaviour Diseases 0.000 description 1
- 238000013500 data storage Methods 0.000 description 1
- 230000007547 defect Effects 0.000 description 1
- 230000000694 effects Effects 0.000 description 1
- 238000012544 monitoring process Methods 0.000 description 1
- 238000011022 operating instruction Methods 0.000 description 1
- 230000008520 organization Effects 0.000 description 1
- 238000006467 substitution reaction Methods 0.000 description 1
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1408—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
- H04L63/1416—Event detection, e.g. attack signature detection
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1408—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
- H04L63/1425—Traffic logging, e.g. anomaly detection
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
Description
Claims (4)
Priority Applications (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN202010013135.7A CN111010409B (zh) | 2020-01-07 | 2020-01-07 | 加密攻击网络流量检测方法 |
| PCT/CN2021/070252 WO2021139643A1 (zh) | 2020-01-07 | 2021-01-05 | 加密攻击网络流量检测方法,其装置及电子设备 |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN202010013135.7A CN111010409B (zh) | 2020-01-07 | 2020-01-07 | 加密攻击网络流量检测方法 |
Publications (2)
| Publication Number | Publication Date |
|---|---|
| CN111010409A CN111010409A (zh) | 2020-04-14 |
| CN111010409B true CN111010409B (zh) | 2021-08-17 |
Family
ID=70120473
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| CN202010013135.7A Active CN111010409B (zh) | 2020-01-07 | 2020-01-07 | 加密攻击网络流量检测方法 |
Country Status (2)
| Country | Link |
|---|---|
| CN (1) | CN111010409B (zh) |
| WO (1) | WO2021139643A1 (zh) |
Families Citing this family (12)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN111010409B (zh) * | 2020-01-07 | 2021-08-17 | 南京林业大学 | 加密攻击网络流量检测方法 |
| CN113542195B (zh) * | 2020-04-16 | 2023-05-05 | 北京观成科技有限公司 | 一种恶意加密流量的检测方法、系统和设备 |
| CN113645176B (zh) * | 2020-05-11 | 2023-08-08 | 北京观成科技有限公司 | 一种检测伪造流量的方法、装置及电子设备 |
| CN112383489A (zh) * | 2020-11-16 | 2021-02-19 | 中国信息通信研究院 | 一种网络数据流量转发方法和装置 |
| CN112565269B (zh) * | 2020-12-07 | 2023-09-05 | 深信服科技股份有限公司 | 服务器后门流量检测方法、装置、电子设备及存储介质 |
| CN113923021B (zh) * | 2021-10-09 | 2023-09-22 | 中国联合网络通信集团有限公司 | 基于沙箱的加密流量处理方法、系统、设备及介质 |
| CN114500122B (zh) * | 2022-04-18 | 2022-07-01 | 国家计算机网络与信息安全管理中心江苏分中心 | 一种基于多源数据融合的特定网络行为分析方法和系统 |
| CN114826741B (zh) * | 2022-04-27 | 2024-02-09 | 新华三信息安全技术有限公司 | 一种攻击监测系统及攻击监测方法 |
| CN116132034A (zh) * | 2023-01-19 | 2023-05-16 | 中国银联股份有限公司 | 数据处理方法、装置、设备及存储介质 |
| CN116112289B (zh) * | 2023-04-10 | 2023-06-16 | 北京长亭未来科技有限公司 | 一种恶意加密流量检测方法以及装置 |
| CN118802681B (zh) * | 2024-03-29 | 2025-11-18 | 中移(杭州)信息技术有限公司 | 违规业务检测方法及装置 |
| CN118316730B (zh) * | 2024-06-04 | 2025-01-21 | 国家计算机网络与信息安全管理中心 | 一种针对邮箱的网络攻击异常行为检测方法 |
Citations (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN107360159A (zh) * | 2017-07-11 | 2017-11-17 | 中国科学院信息工程研究所 | 一种识别异常加密流量的方法及装置 |
| CN107528812A (zh) * | 2016-06-21 | 2017-12-29 | 北京金山云网络技术有限公司 | 一种攻击检测方法及装置 |
| CN108737333A (zh) * | 2017-04-17 | 2018-11-02 | 腾讯科技(深圳)有限公司 | 一种数据检测方法以及装置 |
| CN109462586A (zh) * | 2018-11-08 | 2019-03-12 | 北京知道创宇信息技术有限公司 | 流量监测方法、装置及执行服务器 |
| US10262135B1 (en) * | 2016-12-13 | 2019-04-16 | Symantec Corporation | Systems and methods for detecting and addressing suspicious file restore activities |
| CN109787937A (zh) * | 2017-11-14 | 2019-05-21 | 龙芯中科技术有限公司 | 访问次数的计数方法、装置及服务器 |
Family Cites Families (13)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN101686235B (zh) * | 2008-09-26 | 2013-04-24 | 北京神州绿盟信息安全科技股份有限公司 | 网络异常流量分析设备和方法 |
| CN103139206B (zh) * | 2013-01-31 | 2016-06-01 | 北京神州绿盟信息安全科技股份有限公司 | 一种僵尸主机的检测方法及装置 |
| US20180083990A1 (en) * | 2015-04-20 | 2018-03-22 | John Richard Abe | Network Security Device and Application |
| CN105553974A (zh) * | 2015-12-14 | 2016-05-04 | 中国电子信息产业集团有限公司第六研究所 | 一种http慢速攻击的防范方法 |
| US10027694B1 (en) * | 2016-03-28 | 2018-07-17 | Amazon Technologies, Inc. | Detecting denial of service attacks on communication networks |
| CN107360118B (zh) * | 2016-05-09 | 2021-02-26 | 中国移动通信集团四川有限公司 | 一种高级持续威胁攻击防护方法及装置 |
| EP3422659A1 (en) * | 2017-06-30 | 2019-01-02 | Thomson Licensing | Method of blocking distributed denial of service attacks and corresponding apparatus |
| CN108400963A (zh) * | 2017-10-23 | 2018-08-14 | 平安科技(深圳)有限公司 | 电子装置、访问请求控制方法和计算机可读存储介质 |
| CN110391988B (zh) * | 2018-04-16 | 2023-05-02 | 阿里巴巴集团控股有限公司 | 网络流量控制方法、系统及安全防护装置 |
| CN109450721B (zh) * | 2018-09-06 | 2023-04-18 | 南京聚铭网络科技有限公司 | 一种基于深度神经网络的网络异常行为识别方法 |
| CN110213227B (zh) * | 2019-04-24 | 2020-12-22 | 华为技术有限公司 | 一种网络数据流检测方法及装置 |
| CN110493260A (zh) * | 2019-09-12 | 2019-11-22 | 贵州电网有限责任公司 | 一种网络洪范攻击行为检测方法 |
| CN111010409B (zh) * | 2020-01-07 | 2021-08-17 | 南京林业大学 | 加密攻击网络流量检测方法 |
-
2020
- 2020-01-07 CN CN202010013135.7A patent/CN111010409B/zh active Active
-
2021
- 2021-01-05 WO PCT/CN2021/070252 patent/WO2021139643A1/zh not_active Ceased
Patent Citations (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN107528812A (zh) * | 2016-06-21 | 2017-12-29 | 北京金山云网络技术有限公司 | 一种攻击检测方法及装置 |
| US10262135B1 (en) * | 2016-12-13 | 2019-04-16 | Symantec Corporation | Systems and methods for detecting and addressing suspicious file restore activities |
| CN108737333A (zh) * | 2017-04-17 | 2018-11-02 | 腾讯科技(深圳)有限公司 | 一种数据检测方法以及装置 |
| CN107360159A (zh) * | 2017-07-11 | 2017-11-17 | 中国科学院信息工程研究所 | 一种识别异常加密流量的方法及装置 |
| CN109787937A (zh) * | 2017-11-14 | 2019-05-21 | 龙芯中科技术有限公司 | 访问次数的计数方法、装置及服务器 |
| CN109462586A (zh) * | 2018-11-08 | 2019-03-12 | 北京知道创宇信息技术有限公司 | 流量监测方法、装置及执行服务器 |
Also Published As
| Publication number | Publication date |
|---|---|
| CN111010409A (zh) | 2020-04-14 |
| WO2021139643A1 (zh) | 2021-07-15 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| CN111010409B (zh) | 加密攻击网络流量检测方法 | |
| US9838426B2 (en) | Honeyport active network security | |
| US11316878B2 (en) | System and method for malware detection | |
| US10855700B1 (en) | Post-intrusion detection of cyber-attacks during lateral movement within networks | |
| US8918875B2 (en) | System and method for ARP anti-spoofing security | |
| EP3297248B1 (en) | System and method for generating rules for attack detection feedback system | |
| US10616258B2 (en) | Security information and event management | |
| US9661008B2 (en) | Network monitoring apparatus, network monitoring method, and network monitoring program | |
| CN108809970B (zh) | 一种智能家居安全网关的安全防护方法 | |
| US10257213B2 (en) | Extraction criterion determination method, communication monitoring system, extraction criterion determination apparatus and extraction criterion determination program | |
| US10999304B2 (en) | Bind shell attack detection | |
| EP3066608A1 (en) | Context-aware network forensics | |
| CN104778404A (zh) | 信息处理装置及非法活动判定方法 | |
| CN104937886A (zh) | 日志分析装置、信息处理方法以及程序 | |
| US20170070518A1 (en) | Advanced persistent threat identification | |
| CN102594825A (zh) | 一种内网木马的检测方法和装置 | |
| CN114531271A (zh) | 一种恶意流量检测方法和装置 | |
| CN121464606A (zh) | 检测操作技术协议中的异常网络行为 | |
| US11683337B2 (en) | Harvesting fully qualified domain names from malicious data packets | |
| CN100424609C (zh) | 分析和处理来自网络入侵检测系统的警报的方法和系统 | |
| KR20050095147A (ko) | 침해유형별 시나리오를 고려한 침입방어장치 및 그 방법 | |
| CN115296893A (zh) | 一种地址信息异常检测的方法、装置、系统及介质 | |
| US10454965B1 (en) | Detecting network packet injection | |
| CN112994950A (zh) | 告警误报排除方法、装置及计算机可读介质 | |
| JP2004248198A (ja) | DoS攻撃防御方法及び装置 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| PB01 | Publication | ||
| PB01 | Publication | ||
| SE01 | Entry into force of request for substantive examination | ||
| SE01 | Entry into force of request for substantive examination | ||
| GR01 | Patent grant | ||
| GR01 | Patent grant | ||
| EE01 | Entry into force of recordation of patent licensing contract | ||
| EE01 | Entry into force of recordation of patent licensing contract |
Application publication date: 20200414 Assignee: Nanjing Maoting Information Technology Co.,Ltd. Assignor: NANJING FORESTRY University Contract record no.: X2022980009942 Denomination of invention: Network traffic detection method of encryption attack Granted publication date: 20210817 License type: Common License Record date: 20220706 |
|
| EE01 | Entry into force of recordation of patent licensing contract | ||
| EE01 | Entry into force of recordation of patent licensing contract |
Application publication date: 20200414 Assignee: Nanjing gansijie Photoelectric Technology Co.,Ltd. Assignor: NANJING FORESTRY University Contract record no.: X2022980024612 Denomination of invention: Network Traffic Detection Method for Encryption Attacks Granted publication date: 20210817 License type: Common License Record date: 20221207 |
|
| TR01 | Transfer of patent right | ||
| TR01 | Transfer of patent right |
Effective date of registration: 20241126 Address after: Room 916, Building B2, Longgang Science and Technology Park, Hengyuan Road, Nanjing Economic and Technological Development Zone, Nanjing City, Jiangsu Province 210000 Patentee after: Nanjing gansijie Photoelectric Technology Co.,Ltd. Country or region after: China Address before: No. 159, dragon pan Road, Nanjing, Jiangsu Patentee before: NANJING FORESTRY University Country or region before: China |