首页> 外国专利> DETECTION METHOD FOR APT ATTACK, TERMINAL DEVICE, SERVER AND SYSTEM

DETECTION METHOD FOR APT ATTACK, TERMINAL DEVICE, SERVER AND SYSTEM

机译:APT攻击,终端设备,服务器和系统的检测方法

摘要

Disclosed are a detection method for an APT attack, a terminal device, a server and a system, which relate to the technical field of information security and are primarily used for realizing rapid and precise detection of APT attacks. The primary technical solution of the present invention comprises: a terminal device recording attribute information about a pre-set file in a local area network, wherein the attribute information about the pre-set file comprises identification information, time information, source information, and transfer target information; determining whether the pre-set file is a grey file according to the attribute information, wherein the grey file neither exists in a white list of the pre-set file nor a black list in the pre-set file; if it is determined that the pre-set file is a grey file, then determining whether the grey file has triggered a pre-set abnormal behaviour rule; and if it is determined that the grey file has triggered the pre-set abnormal behaviour rule, sending to a server abnormality alarm information about the grey file having triggered the pre-set abnormal behaviour rule, wherein the abnormality alarm information contains identification information about the terminal device. The present invention is primarily applied in the process of detecting an APT attack.
机译:本发明公开了一种APT攻击的检测方法,终端设备,服务器和系统,涉及信息安全技术领域,主要用于实现对APT攻击的快速,精确检测。本发明的主要技术方案包括:终端设备,在局域网中记录有关预设文件的属性信息,其中,所述预设文件的属性信息包括标识信息,时间信息,源信息和传输信息。目标信息;根据所述属性信息确定所述预设文件是否为灰色文件,所述灰色文件既不存在于所述预设文件的白名单中也不存在于所述预设文件中的黑名单中;如果确定所述预设文件为灰色文件,则判断所述灰色文件是否触发了预设的异常行为规则;如果确定灰色文件已经触发了预设的异常行为规则,则将已经触发了预设的异常行为规则的灰色文件的异常告警信息发送给服务器,其中,异常告警信息中包含有关于终端设备。本发明主要应用于检测APT攻击的过程中。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号