APT detection method based on matching of flow fingerprint and communication features
A technology of communication features and detection methods, applied in electrical components, transmission systems, etc., can solve problems such as being difficult to be detected in advance, and achieve the effect of improving detection accuracy and speed of discovery
- Summary
- Abstract
- Description
- Claims
- Application Information
AI Technical Summary
Problems solved by technology
Method used
Image
Examples
Embodiment Construction
[0022] It should be noted that, in the case of no conflict, the embodiments of the present invention and the features in the embodiments can be combined with each other.
[0023] Specific embodiments of the invention will be described in detail below.
[0024] A kind of APT detection method based on traffic fingerprint and communication feature matching, comprises the following steps:
[0025] Use sniff to collect traffic data, then use pyshark to analyze network packets, obtain source and destination IP addresses, source and destination ports, protocol types, and traffic packet sizes in traffic packets, and save traffic fingerprints including the above metadata to form network traffic Fingerprint library; the hardware system corresponding to this step is defined as the traffic feature extraction module;
[0026] Select URLs and HOSTs of well-known websites in the Internet and websites that are often used in daily life to build a communication feature library; the corresp...
PUM
Abstract
Description
Claims
Application Information
- R&D Engineer
- R&D Manager
- IP Professional
- Industry Leading Data Capabilities
- Powerful AI technology
- Patent DNA Extraction
Browse by: Latest US Patents, China's latest patents, Technical Efficacy Thesaurus, Application Domain, Technology Topic, Popular Technical Reports.
© 2024 PatSnap. All rights reserved.Legal|Privacy policy|Modern Slavery Act Transparency Statement|Sitemap|About US| Contact US: help@patsnap.com