首页> 外国专利> APPARATUS AND METHOD FOR DETECTING ATTACK BY USING LOG ANALYSIS

APPARATUS AND METHOD FOR DETECTING ATTACK BY USING LOG ANALYSIS

机译:利用对数分析检测攻击的装置和方法

摘要

Attack detection apparatus using a log analysis according to an embodiment of the present invention is a log analysis unit for detecting the occurrence of a predetermined event based on the log of the terminal, each of a series of events generated when the cyber attack proceeds from the leaf node On the basis of the tree structure mapped in order to each node connected to the root node, an attack detection unit for determining whether a predetermined event exists among the events mapped to each node and a predetermined event are directed from one leaf node to the root node. When the attack detection unit determines that the predetermined level of the tree structure occurs to the predetermined level of the event mapped to each connected node, the attack counter includes an attack counter that performs a corresponding operation for responding to the cyber attack.
机译:根据本发明实施例的使用日志分析的攻击检测设备是日志分析单元,用于基于终端的日志来检测预定事件的发生,当从网络攻击发起网络攻击时生成一系列事件中的每一个。叶节点基于顺序映射到与根节点连接的每个节点的树结构,攻击检测单元用于确定映射到每个节点的事件中是否存在预定事件,并将预定事件从一个叶节点定向到根节点。当攻击检测单元确定树结构的预定级别发生在映射到每个连接的节点的事件的预定级别时,攻击计数器包括攻击计数器,该攻击计数器执行用于响应网络攻击的相应操作。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号