首页> 外文会议>IEEE International Conference on Electronics Information and Emergency Communication >Research and Application of APT Attack Defense and Detection Technology Based on Big Data Technology
【24h】

Research and Application of APT Attack Defense and Detection Technology Based on Big Data Technology

机译:基于大数据技术的APT攻击防御和检测技术研究与应用

获取原文

摘要

In order to excavate security threats in power grid by making full use of heterogeneous data sources in power information system, this paper proposes APT (Advanced Persistent Threat) attack detection sandbox technology and active defense system based on big data analysis technology. First, the file is restored from the mirror traffic and executed statically. Then, sandbox execution was carried out to introduce analysis samples into controllable virtual environment, and dynamic analysis and operation samples were conducted. Through analyzing the dynamic processing process of samples, various known and unknown malicious code, APT attacks, high-risk Trojan horses and other network security risks were comprehensively detected. Finally, the threat assessment of malicious samples is carried out and visualized through the big data platform. The results show that the method proposed in this paper can effectively warn of unknown threats, improve the security level of system data, have a certain active defense ability. And it can effectively improve the speed and accuracy of power information system security situation prediction.
机译:为了通过在电力信息系统中充分利用异构数据来源来挖掘电网中的安全威胁,本文提出了基于大数据分析技术的APT(高级持久威胁)攻击检测沙箱技术和主动防御系统。首先,将从镜像流量恢复并静态执行。然后,进行沙箱执行以将分析样本引入可控虚拟环境,并进行动态分析和操作样本。通过分析样本的动态处理过程,综合地检测到各种已知和未知的恶意代码,APT攻击,高风险的特洛伊木马和其他网络安全风险。最后,通过大数据平台进行恶意样本的威胁评估。结果表明,本文提出的方法可以有效地警告未知的威胁,提高系统数据的安全水平,具有一定的主动防御能力。它可以有效提高电力信息系统安全性能预测的速度和准确性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号