CN111600863B - 网络入侵检测方法、装置、系统和存储介质 - Google Patents
网络入侵检测方法、装置、系统和存储介质 Download PDFInfo
- Publication number
- CN111600863B CN111600863B CN202010389531.XA CN202010389531A CN111600863B CN 111600863 B CN111600863 B CN 111600863B CN 202010389531 A CN202010389531 A CN 202010389531A CN 111600863 B CN111600863 B CN 111600863B
- Authority
- CN
- China
- Prior art keywords
- packet
- data
- parameters
- data packet
- protocol
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Active
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1408—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
- H04L63/1416—Event detection, e.g. attack signature detection
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L69/00—Network arrangements, protocols or services independent of the application payload and not provided for in the other groups of this subclass
- H04L69/06—Notations for structuring of protocol data, e.g. abstract syntax notation one [ASN.1]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L69/00—Network arrangements, protocols or services independent of the application payload and not provided for in the other groups of this subclass
- H04L69/22—Parsing or analysis of headers
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
- Computer And Data Communications (AREA)
Abstract
Description
Claims (8)
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN202010389531.XA CN111600863B (zh) | 2020-05-08 | 2020-05-08 | 网络入侵检测方法、装置、系统和存储介质 |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN202010389531.XA CN111600863B (zh) | 2020-05-08 | 2020-05-08 | 网络入侵检测方法、装置、系统和存储介质 |
Publications (2)
| Publication Number | Publication Date |
|---|---|
| CN111600863A CN111600863A (zh) | 2020-08-28 |
| CN111600863B true CN111600863B (zh) | 2022-09-13 |
Family
ID=72183850
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| CN202010389531.XA Active CN111600863B (zh) | 2020-05-08 | 2020-05-08 | 网络入侵检测方法、装置、系统和存储介质 |
Country Status (1)
| Country | Link |
|---|---|
| CN (1) | CN111600863B (zh) |
Families Citing this family (7)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN112640392B (zh) * | 2020-11-20 | 2022-05-13 | 华为技术有限公司 | 一种木马检测方法、装置和设备 |
| CN112887405B (zh) * | 2021-01-26 | 2022-09-30 | 深信服科技股份有限公司 | 一种入侵防御方法、系统及相关设备 |
| CN115208596B (zh) * | 2021-04-09 | 2023-09-19 | 中国移动通信集团江苏有限公司 | 网络入侵防御方法、装置及存储介质 |
| CN113259160A (zh) * | 2021-05-11 | 2021-08-13 | 杭州安恒信息安全技术有限公司 | 工控网络的点位信息预警方法、装置和电子装置 |
| CN114462023A (zh) * | 2022-01-21 | 2022-05-10 | 内蒙古工业大学 | 一种用于发电厂控制系统的蜜罐防御控制方法及装置 |
| CN114978782B (zh) * | 2022-08-02 | 2022-11-01 | 北京六方云信息技术有限公司 | 工控威胁检测方法、装置、工控设备以及存储介质 |
| CN115065568B (zh) * | 2022-08-19 | 2022-12-20 | 北京珞安科技有限责任公司 | 一种工控网络入侵检测方法及系统 |
Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN101800989A (zh) * | 2010-01-19 | 2010-08-11 | 重庆邮电大学 | 用于工业无线网络的防重放攻击系统 |
| CN105429963A (zh) * | 2015-11-04 | 2016-03-23 | 北京工业大学 | 基于Modbus/Tcp的入侵检测分析方法 |
| CN107438052A (zh) * | 2016-05-26 | 2017-12-05 | 中国科学院沈阳自动化研究所 | 一种面向未知工业通信协议规约的异常行为检测方法 |
Family Cites Families (8)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| EP2815282A4 (en) * | 2012-02-17 | 2015-08-19 | Vencore Labs Inc | METHOD AND SYSTEM FOR PACKAGE DETECTION, ANALYSIS AND IMPACT DETECTION AT FIELD BUSES |
| CN105204487A (zh) * | 2014-12-26 | 2015-12-30 | 北京邮电大学 | 基于通信模型的工业控制系统的入侵检测方法及系统 |
| US10291506B2 (en) * | 2015-03-04 | 2019-05-14 | Fisher-Rosemount Systems, Inc. | Anomaly detection in industrial communications networks |
| CN106254316B (zh) * | 2016-07-20 | 2019-07-05 | 北京工业大学 | 一种基于数据依赖的工控行为异常检测系统 |
| CN106603531A (zh) * | 2016-12-15 | 2017-04-26 | 中国科学院沈阳自动化研究所 | 一种基于工业控制网络的入侵检测模型的自动建立方法及装置 |
| CN108810034A (zh) * | 2018-08-20 | 2018-11-13 | 杭州安恒信息技术股份有限公司 | 一种工业控制系统信息资产的安全防护方法 |
| CN109743187B (zh) * | 2018-11-23 | 2021-11-16 | 奇安信科技集团股份有限公司 | 工控网络异常检测方法及装置 |
| CN110096013A (zh) * | 2019-05-24 | 2019-08-06 | 广东工业大学 | 一种工业控制系统的入侵检测方法及装置 |
-
2020
- 2020-05-08 CN CN202010389531.XA patent/CN111600863B/zh active Active
Patent Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN101800989A (zh) * | 2010-01-19 | 2010-08-11 | 重庆邮电大学 | 用于工业无线网络的防重放攻击系统 |
| CN105429963A (zh) * | 2015-11-04 | 2016-03-23 | 北京工业大学 | 基于Modbus/Tcp的入侵检测分析方法 |
| CN107438052A (zh) * | 2016-05-26 | 2017-12-05 | 中国科学院沈阳自动化研究所 | 一种面向未知工业通信协议规约的异常行为检测方法 |
Non-Patent Citations (2)
| Title |
|---|
| 基于行为模型的工控异常检测方法研究;宋站威等;《计算机科学》;20180115(第01期);第242-248页 * |
| 工业控制系统入侵检测技术综述;杨安等;《计算机研究与发展》;20160915(第09期);第150-165页 * |
Also Published As
| Publication number | Publication date |
|---|---|
| CN111600863A (zh) | 2020-08-28 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| CN111600863B (zh) | 网络入侵检测方法、装置、系统和存储介质 | |
| KR102163280B1 (ko) | 엣지 컴퓨팅 기반 네트워크 모니터링 방법, 장치 및 시스템 | |
| CN104937886B (zh) | 日志分析装置、信息处理方法 | |
| CN101567812B (zh) | 对网络攻击进行检测的方法和装置 | |
| US8347383B2 (en) | Network monitoring apparatus, network monitoring method, and network monitoring program | |
| US20060161816A1 (en) | System and method for managing events | |
| CN103491060B (zh) | 一种防御Web攻击的方法、装置、及系统 | |
| EP3304813A1 (en) | Network behavior data collection and analytics for anomaly detection | |
| CN106357470B (zh) | 一种基于sdn控制器网络威胁快速感知方法 | |
| CN109462621A (zh) | 网络安全保护方法、装置及电子设备 | |
| CN107911244A (zh) | 一种云网结合的多用户蜜罐终端系统及其实现方法 | |
| Neu et al. | Lightweight IPS for port scan in OpenFlow SDN networks | |
| CN101197715A (zh) | 一种移动数据业务状态的安全集中采集方法 | |
| CN112769833B (zh) | 命令注入攻击的检测方法、装置、计算机设备和存储介质 | |
| CN110049015B (zh) | 网络安全态势感知系统 | |
| CN106453434A (zh) | 一种网络流量的监测方法及监测系统 | |
| Qiu et al. | Global Flow Table: A convincing mechanism for security operations in SDN | |
| CN100435513C (zh) | 网络设备与入侵检测系统联动的方法 | |
| CN113285937B (zh) | 一种基于传统变电站配置文件和iec103协议流量的安全审计方法及系统 | |
| JP4328679B2 (ja) | コンピュータネットワークの運用監視方法及び装置並びにプログラム | |
| CN205510080U (zh) | 用于大型网络的安全管理平台 | |
| Pekarčík et al. | A Centralized Approach to Intrusion Detection System Management: Design, Implementation and Evaluation | |
| CN116112295B (zh) | 一种外连类攻击结果研判方法及装置 | |
| CN103248505A (zh) | 基于视图的网络监控方法及装置 | |
| Hintze et al. | InfiniBand network monitoring: Challenges and possibilities |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| PB01 | Publication | ||
| PB01 | Publication | ||
| SE01 | Entry into force of request for substantive examination | ||
| SE01 | Entry into force of request for substantive examination | ||
| GR01 | Patent grant | ||
| GR01 | Patent grant | ||
| EE01 | Entry into force of recordation of patent licensing contract | ||
| EE01 | Entry into force of recordation of patent licensing contract |
Application publication date: 20200828 Assignee: Hangzhou Anheng Information Security Technology Co.,Ltd. Assignor: Dbappsecurity Co.,Ltd. Contract record no.: X2024980043366 Denomination of invention: Network intrusion detection methods, devices, systems, and storage media Granted publication date: 20220913 License type: Common License Record date: 20241231 |
|
| TR01 | Transfer of patent right | ||
| TR01 | Transfer of patent right |
Effective date of registration: 20250511 Address after: No. 10-1-2, Building 1, West Zone, Ningbo New Materials Innovation Center, High tech Zone, Ningbo City, Zhejiang Province 315000 Patentee after: Ningbo Ningshu Security Technology Co.,Ltd. Country or region after: China Address before: No. 188, Lianhui street, Xixing street, Binjiang District, Hangzhou City, Zhejiang Province Patentee before: Dbappsecurity Co.,Ltd. Country or region before: China |