Method and device for detecting hackers in associated manner

The embodiment of the invention provides a method and a device for detecting hackers in an associated manner, and the method comprises the steps: extracting first network information for representinga hacker intrusion event based on the hacker intrusion event; based on the first network information,...

Ausführliche Beschreibung

Gespeichert in:
Bibliographische Detailangaben
1. Verfasser: HUANG YUNYU
Format: Patent
Sprache:chi ; eng
Schlagworte:
Online-Zugang:Volltext bestellen
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
Beschreibung
Zusammenfassung:The embodiment of the invention provides a method and a device for detecting hackers in an associated manner, and the method comprises the steps: extracting first network information for representinga hacker intrusion event based on the hacker intrusion event; based on the first network information, performing association to obtain second network information used for representing the hacker intrusion event; and based on the second network information, performing association to obtain first target information used for representing the hacker intrusion event. According to the method and the device for detecting hackers in a correlation manner, the latest threats of a hacker organization can be automatically detected and tracked in a correlation manner in a large range; therefore, the latestthreat event of the hacker organization is rapidly and efficiently evaluated in an associated mode, the accuracy of malicious domain name recognition is improved, and the harm degree and the influence range of the hacker orga