Malicious domain name identification method and device and storage medium
The invention provides a malicious domain name identification method. The method comprises the steps of: obtaining a domain name to be detected, performing virus flow matching on the domain name to bedetected; obtaining a first matching result, if the first matching result represents that the virus...
Gespeichert in:
Hauptverfasser: | , |
---|---|
Format: | Patent |
Sprache: | chi ; eng |
Schlagworte: | |
Online-Zugang: | Volltext bestellen |
Tags: |
Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
|
Zusammenfassung: | The invention provides a malicious domain name identification method. The method comprises the steps of: obtaining a domain name to be detected, performing virus flow matching on the domain name to bedetected; obtaining a first matching result, if the first matching result represents that the virus flow matching is failed, adopting a matching mode of at least one dimension; matching the domain name to be detected, obtaining a second matching result, wherein the at least one dimension comprises an attribute dimension, a rule dimension or a third-party information dimension; and when the secondmatching result represents that the matching is successful, and based on the second matching result, marking the domain name to be detected to obtain a final identification result, and judging whether the domain name to be detected is the malicious domain name according to the attribute of the domain name to be detected, so that providing of proof information when the domain name to be detected belongs to a certain virus |
---|