Attack URL (Uniform Resource Locator) detection method, device and system based on behavior pattern
The invention discloses an attack URL (Uniform Resource Locator) detection method, device and system based on a behavior pattern, relates to research on an attack URL detection method in Web security, is a method for automatically detecting and extracting based on behavior characteristics in a netwo...
Gespeichert in:
Hauptverfasser: | , , , , |
---|---|
Format: | Patent |
Sprache: | chi ; eng |
Schlagworte: | |
Online-Zugang: | Volltext bestellen |
Tags: |
Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
|
Zusammenfassung: | The invention discloses an attack URL (Uniform Resource Locator) detection method, device and system based on a behavior pattern, relates to research on an attack URL detection method in Web security, is a method for automatically detecting and extracting based on behavior characteristics in a network attack early-stage detection stage, and aims to realize automatic detection and extraction by utilizing a trampling behavior, namely detection-failure, commonly existing in a hacker attack early-stage. As an attack URL identification feature, the method is suitable for early discovery and detection of unknown attack behaviors. Due to the fact that the set judgment conditions are very clear and simple, the false alarm rate and the missing report rate are both low, particularly, no priori attack knowledge is needed, and the effect of preventing unknown attacks in advance can be achieved.
本发明公开了一种基于行为模式的攻击URL检测方法、装置和系统,涉及Web安全中攻击URL检测方法研究,是一种基于网络攻击前期探测阶段的行为特征进行自动检测并提取的方法,利用黑客攻击前期普遍存在的"踩点"行为,即"探测-失败",作为攻击URL的识别特征,适用 |
---|