White data filter method and system in APT (Advanced Persistent Threat) intelligent detection and analysis platform
An intelligent detection and data technology, applied in the field of white data filtering methods and systems, can solve problems such as analysis difficulties, and achieve the effects of improving analysis efficiency, saving hardware costs, and relieving storage pressure.
- Summary
- Abstract
- Description
- Claims
- Application Information
AI Technical Summary
Problems solved by technology
Method used
Image
Examples
Embodiment 1
[0051] Embodiment 1, a method for filtering white data in an APT intelligent detection and analysis platform, comprising:
[0052] Perform protocol analysis on each Pcap (packet capture library, packet capture library) data packet in the stored historical flow data respectively, and obtain the control information and data of each Pcap data packet;
[0053] Generate filter rules according to predetermined white data filter conditions;
[0054]The control information of each Pcap packet analyzed is matched with the filter rule, if the control information of a Pcap packet satisfies the filter rule, then delete the control information and data of the Pcap packet;
[0055] After the deletion, the remaining data and control information (that is, the control information and data of the Pcap data packet that has not been deleted) are repackaged and encapsulated into a Pcap data packet and sent to the APT search engine.
[0056] In this embodiment, the white data filtering conditions ...
Embodiment 2
[0072] Embodiment 2, a white data filtering system in an APT intelligent detection and analysis platform, such as figure 2 shown, including:
[0073] Protocol analysis module 101, is used for carrying out agreement analysis respectively to the Pcap file in the historical flow data of storage, obtains the control information and the application data content of each Pcap packet;
[0074] A rule generation module 102, configured to generate filter rules according to predetermined white data filter conditions;
[0075] Data deletion module 103 is used to match the control information of each Pcap packet analyzed with the filter rule, if the control information of a Pcap packet satisfies the filter rule, then delete the control information and the filter rule of the Pcap packet application data content;
[0076] The file operation module 104 is used to repackage and encapsulate the remaining application data content and control information after deletion into a Pcap data packet ...
PUM
Abstract
Description
Claims
Application Information
- R&D Engineer
- R&D Manager
- IP Professional
- Industry Leading Data Capabilities
- Powerful AI technology
- Patent DNA Extraction
Browse by: Latest US Patents, China's latest patents, Technical Efficacy Thesaurus, Application Domain, Technology Topic, Popular Technical Reports.
© 2024 PatSnap. All rights reserved.Legal|Privacy policy|Modern Slavery Act Transparency Statement|Sitemap|About US| Contact US: help@patsnap.com