首页> 外国专利> ATTACK PATH DETECTION METHOD, ATTACK PATH DETECTION SYSTEM AND NON-TRANSITORY COMPUTER-READABLE MEDIUM

ATTACK PATH DETECTION METHOD, ATTACK PATH DETECTION SYSTEM AND NON-TRANSITORY COMPUTER-READABLE MEDIUM

机译:攻击路径检测方法,攻击路径检测系统和非暂时性计算机可读介质

摘要

An attack path detection method, attack path detection system and non-transitory computer-readable medium are provided in this disclosure. The attack path detection method includes the following operations: establishing a connecting relationship among a plurality of hosts according to a host log set to generate a host association graph; labeling at least one host with an abnormal condition on the host association graph; calculating a risk value corresponding to each of the plurality of hosts; in a host without the abnormal condition, determining whether the risk value corresponding to the host without the abnormal condition is greater than a first threshold, and utilizing a host with the risk value greater than the first threshold as a high-risk host; and searching at least one host attach path from the high-risk host and the at least one host with the abnormal condition according to the connecting relationship of the host association graph.
机译:在本公开中提供了攻击路径检测方法,攻击路径检测系统和非暂时性计算机可读介质。攻击路径检测方法包括以下操作:根据主机日志设置建立多个主机之间的连接关系以生成主序图;在主机关联图上标记具有异常情况的至少一个主机;计算对应于多个主机中的每一个的风险值;在没有异常条件的主机中,确定与没有异常条件的主机对应的风险值大于第一阈值,并利用具有大于第一阈值的风险值的主机,作为高风险主机;并根据主机关联图的连接关系,在高风险主机和至少一个主机中搜索至少一个主机附加路径。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号