Botnet family scale anomaly detection method and device
The embodiment of the invention relates to a botnet family scale anomaly detection method and device, electronic equipment and a storage medium, and particularly relates to the technical field of network security. The detection method comprises the following steps: counting the number of propagation...
Gespeichert in:
Hauptverfasser: | , , , , , , , , , , , , , , |
---|---|
Format: | Patent |
Sprache: | chi ; eng |
Schlagworte: | |
Online-Zugang: | Volltext bestellen |
Tags: |
Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
|
Zusammenfassung: | The embodiment of the invention relates to a botnet family scale anomaly detection method and device, electronic equipment and a storage medium, and particularly relates to the technical field of network security. The detection method comprises the following steps: counting the number of propagation sources of the botnet family in each predetermined unit duration in a monitoring interval according to historical data; generating a training sample set according to the number of the propagation sources in each predetermined unit duration, and training an isolated forest model according to the training sample set; monitoring the number of propagation sources of the botnet family in the monitoring interval within the predetermined unit duration in real time, and calculating an abnormal value score of the number of propagation sources in the isolated forest model; and performing anomaly detection on propagation of the botnet family according to the abnormal value score, thereby realizing anomaly detection on the fa |
---|