Malicious domain name identification method and device and storage medium

The invention provides a malicious domain name identification method. The method comprises the steps of: obtaining a domain name to be detected, performing virus flow matching on the domain name to bedetected; obtaining a first matching result, if the first matching result represents that the virus...

Ausführliche Beschreibung

Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: ZHANG ZENGRUI, MENG XIANG
Format: Patent
Sprache:chi ; eng
Schlagworte:
Online-Zugang:Volltext bestellen
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
Beschreibung
Zusammenfassung:The invention provides a malicious domain name identification method. The method comprises the steps of: obtaining a domain name to be detected, performing virus flow matching on the domain name to bedetected; obtaining a first matching result, if the first matching result represents that the virus flow matching is failed, adopting a matching mode of at least one dimension; matching the domain name to be detected, obtaining a second matching result, wherein the at least one dimension comprises an attribute dimension, a rule dimension or a third-party information dimension; and when the secondmatching result represents that the matching is successful, and based on the second matching result, marking the domain name to be detected to obtain a final identification result, and judging whether the domain name to be detected is the malicious domain name according to the attribute of the domain name to be detected, so that providing of proof information when the domain name to be detected belongs to a certain virus