首页> 外国专利> LOG ANALYSIS DEVICE, ATTACK DETECTION DEVICE, ATTACK DETECTION METHOD AND PROGRAM

LOG ANALYSIS DEVICE, ATTACK DETECTION DEVICE, ATTACK DETECTION METHOD AND PROGRAM

机译:日志分析设备,攻击检测设备,攻击检测方法和程序

摘要

The log analysis device has: storage unit (12), and for storing a profile, which determines whether there is standard attack information processing unit; Parameter extraction unit (31), these parameters from extract access request; Character string class converting unit (32), for each parameter, more each parameter value and predefined character string class, instead of the component and the character string class to matching length maximum, therefore conversion parameter is class's pupil's handbook in replacement sequence; Profil storage unit (43), it, together just frequently as learning data, stores the frequency occurred in those list of categories in storage unit (12) and is greater than or equal to specified value as profile from one group of list of categories loop-around data access request; With abnormality detecting unit (53), determine whether request is the attack analyzed, according to the above-mentioned class's pupil's handbook of similarity and above-mentioned profile.
机译:该日志分析设备具有:存储单元(12),用于存储简档,该简档确定是否存在标准攻击信息处理单元;以及参数提取单元(31),从提取访问请求中提取这些参数;字符串类别转换单元(32),对于每个参数,更多的是每个参数值和预定义的字符串类别,而不是最大匹配长度的组件和字符串类别,因此转换参数是替换顺序中该类别的学生的手册; Profil存储单元(43)经常作为学习数据一起存储在存储单元(12)中那些类别列表中出现的频率,并且大于或等于指定值作为一组类别列表循环中的配置文件-围绕数据访问请求;利用异常检测单元(53),根据上述班的学生相似度手册和上述概况,确定请求是否被分析了攻击。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号