首页> 外国专利> IPFIX-based detection of amplification attacks on databases

IPFIX-based detection of amplification attacks on databases

机译:基于IPFIX的数据库放大攻击检测

摘要

One embodiment illustrated herein includes a computer implemented method. The method includes acts for training an amplification attack detection system. The method includes obtaining a plurality of samples of IPFIX data. The method further includes using the IPFIX data to create a plurality of time-based, server samples on a per server basis such that each sample corresponds to a server and a period of time over which IPFIX data in the sample corresponds. The method further includes identifying a plurality of the server samples that are labeled positive for amplification attacks. The method further includes identifying a plurality of server samples that are labeled negative for amplification attacks. The method further includes automatically labeling at least some of the remaining server samples as positive or negative based on the previously identified labeled samples. The method further includes using the automatically labeled samples to train an amplification attack detection system.
机译:本文示出的一个实施例包括一种计算机实现的方法。该方法包括用于训练扩增攻击检测系统的动作。该方法包括获得IPFIX数据的多个样本。该方法进一步包括使用IPFIX数据在每个服务器的基础上创建多个基于时间的服务器样本,以使得每个样本对应于一个服务器以及该样本中的IPFIX数据对应的时间段。该方法还包括识别被标记为扩增攻击阳性的多个服务器样本。该方法还包括识别被标记为对扩增攻击为阴性的多个服务器样本。该方法还包括基于先前识别的标记样本将剩余服务器样本中的至少一些自动标记为阳性或阴性。该方法还包括使用自动标记的样本来训练扩增攻击检测系统。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号