首页> 外国专利> GENERATION APPARATUS AND METHOD OF DETECTION RULES FOR ATTACK BEHAVIOR BASED ON INFORMATION OF NETWORK SESSION

GENERATION APPARATUS AND METHOD OF DETECTION RULES FOR ATTACK BEHAVIOR BASED ON INFORMATION OF NETWORK SESSION

机译:基于网络会话信息的攻击行为检测装置及检测方法

摘要

The present invention relates to a method and apparatus for automatically generating and automatically updating attack behavior detection rules for network session characteristic information. The network data classified by session characteristic information may be divided into session characteristic information and normal data type, attack type, and unknown type. Network session feature information extracting unit converting to input data format including properties of belonging network data type and extended C4.5 algorithm applied to network data converted to input data format to construct decision tree, and final node of decision tree Generates the accuracy of decision tree based on error rate, and generates detection rule patterned by network data type based on the characteristics of network data type, conditional expression for selecting node with optimal information gain of decision tree, and accuracy. Detection including automatic detection rule generation Create and update rules automatically.;Network session property information, detection rule, decision tree, auto generation, auto update
机译:本发明涉及一种用于为网络会话特征信息自动生成并自动更新攻击行为检测规则的方法和装置。通过会话特征信息分类的网络数据可以分为会话特征信息和正常数据类型,攻击类型和未知类型。网络会话特征信息提取单元转换为包含所属网络数据类型的属性的输入数据格式,并将扩展的C4.5算法应用于转换为输入数据格式的网络数据以构造决策树,决策树的最终节点生成决策树的准确性基于错误率,基于网络数据类型的特征,具有决策树的最佳信息增益的选择节点的条件表达式和准确性,生成以网络数据类型为模式的检测规则。检测包括自动生成检测规则,自动创建和更新规则。网络会话属性信息,检测规则,决策树,自动生成,自动更新

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号