首页> 外国专利> ABNORMAL COMMUNICATION DETECTION APPARATUS, ABNORMAL COMMUNICATION DETECTION METHOD AND PROGRAM

ABNORMAL COMMUNICATION DETECTION APPARATUS, ABNORMAL COMMUNICATION DETECTION METHOD AND PROGRAM

机译:异常通信检测装置,通信检测方法和程序异常

摘要

There is provided an abnormal communication detection apparatus capable of reducing over-detection. The abnormal communication detection apparatus includes: a receiving part receiving communication data for learning that includes an identifier and communication data for detection that includes the identifier; a knowledge information acquiring part acquiring knowledge information that is information about at least either temporal characteristics or payload characteristics of the communication data for learning; an allocation rule generating part generating allocation rules that are rules for specifying which communication data having which identifier is to be allocated to which detector among a plurality of detectors, based on the knowledge information; an allocating part allocating the communication data to any of the detectors based on the allocation rules; and the plurality of detectors each of which learns, when the communication data for learning is allocated, a model for detecting whether the communication data allocated to the detector is normal or abnormal, and detects, when the communication data for detection is allocated, whether the communication data for detection is normal or abnormal based on the learned model.
机译:提供了一种能够减少过度检测的异常通信检测装置。异常通信检测装置包括:接收部分接收用于学习的通信数据,包括用于检测的标识符和通信数据,包括标识符;知识信息获取部分获取知识信息,即关于至少学习通信数据的至少任一时间特征或有效载荷特性的信息;一种分配规则生成部分生成分配规则,其是用于指定具有该通信数据的规则,该通信数据基于知识信息基于知识信息将其分配给多个检测器之间的检测器的通信数据;将通信数据分配给任何检测器的分配部分基于分配规则;当分配用于学习的通信数据时,多个检测器学习,用于检测分配给检测器的通信数据是正常的还是异常的模型,并且当分配用于检测的通信数据时,检测用于检测的通信数据是基于学习模型的正常或异常。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号