KR20160077009A - 유저 행위 식별 방법 및 유저 행위 식별 장치, 프로그램 및 저장매체 - Google Patents
유저 행위 식별 방법 및 유저 행위 식별 장치, 프로그램 및 저장매체 Download PDFInfo
- Publication number
- KR20160077009A KR20160077009A KR1020157016876A KR20157016876A KR20160077009A KR 20160077009 A KR20160077009 A KR 20160077009A KR 1020157016876 A KR1020157016876 A KR 1020157016876A KR 20157016876 A KR20157016876 A KR 20157016876A KR 20160077009 A KR20160077009 A KR 20160077009A
- Authority
- KR
- South Korea
- Prior art keywords
- access
- time
- space
- sliding window
- predetermined
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Granted
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1408—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
- H04L63/1425—Traffic logging, e.g. anomaly detection
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/10—Network architectures or network communication protocols for network security for controlling access to devices or network resources
- H04L63/108—Network architectures or network communication protocols for network security for controlling access to devices or network resources when the policy decisions are valid for a limited amount of time
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/55—Detecting local intrusion or implementing counter-measures
- G06F21/552—Detecting local intrusion or implementing counter-measures involving long-term monitoring or reporting
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L43/00—Arrangements for monitoring or testing data switching networks
- H04L43/10—Active monitoring, e.g. heartbeat, ping or trace-route
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1441—Countermeasures against malicious traffic
- H04L63/1458—Denial of Service
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F2221/00—Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F2221/21—Indexing scheme relating to G06F21/00 and subgroups addressing additional information or applications relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F2221/2133—Verifying human interaction, e.g., Captcha
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L2463/00—Additional details relating to network architectures or network communication protocols for network security covered by H04L63/00
- H04L2463/121—Timestamp
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L2463/00—Additional details relating to network architectures or network communication protocols for network security covered by H04L63/00
- H04L2463/142—Denial of service attacks against network infrastructure
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L2463/00—Additional details relating to network architectures or network communication protocols for network security covered by H04L63/00
- H04L2463/144—Detection or countermeasures against botnets
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- General Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computing Systems (AREA)
- Software Systems (AREA)
- Theoretical Computer Science (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Health & Medical Sciences (AREA)
- Cardiology (AREA)
- General Health & Medical Sciences (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
- Storage Device Security (AREA)
- Debugging And Monitoring (AREA)
- Information Transfer Between Computers (AREA)
- Management, Administration, Business Operations System, And Electronic Commerce (AREA)
Abstract
Description
도 1은 예시적인 일 실시예에 따른 유저 행위 식별 방법의 흐름도이다.
도 2는 예시적인 일 실시예에 따른 유저 행위 식별 방법의 흐름도이다.
도 3은 예시적인 일 실시예에 따른 유저 행위 식별 방법의 흐름도이다.
도 4는 예시적인 일 실시예에 따른 유저 행위 식별 장치의 블럭도이다.
도 5는 예시적인 일 실시예에 따른 평가 모듈의 블럭도이다.
도 6 A는 예시적인 일 실시예에 따른 평가 모듈의 블럭도이다.
도 6 B는 예시적인 일 실시예에 따른 평가 모듈의 블럭도이다.
도 7은 예시적인 일 실시예에 따른 평가 모듈의 블럭도이다.
도 8은 예시적인 일 실시예에 따른 장치의 블럭도이다.
Claims (11)
- 소정의 시공간 슬라이딩 윈도우(time sliding window)내의 단말기에 의한 액세스(access) 행위를 취득하는 스텝(step)과,
상기 시공간 슬라이딩 윈도우내의 액세스 행위에 근거하여 상기 시공간 슬라이딩 윈도우내의 액세스 행위를 평가하는 스텝과,
그 평가 결과에 근거하여 상기 단말기에 의한 액세스 행위가 악의적인 액세스인지를 판단하는 스텝
을 포함하는 것을 특징으로 하는 유저 행위 식별 방법.
- 제 1항에 있어서,
상기 시공간 슬라이딩 윈도우는 m개로 등분 된 타임 슬라이스(time slices)를 포함하고,
상기 시공간 슬라이딩 윈도우내의 액세스 행위에 근거하여 상기 시공간 슬라이딩 윈도우내의 액세스 행위를 평가하는 스텝은
타임 슬라이스내의 액세스 횟수가 소정의 슬라이스 횟수 역치를 초과하는지를 타임 슬라이스마다 판단하여, 액세스 횟수가 소정의 슬라이스 횟수 역치를 초과하는 n개의 타임 슬라이스를 취득하는 스텝과,
n와 m의 비례가 소정의 제1 비례 역치를 초과하는지 여부를 판단하는 스텝
을 포함하고,
그 평가 결과에 근거하여 상기 단말기에 의한 액세스 행위가 악의적인 액세스인지를 판단하는 스텝은
n와 m의 비례가 소정의 제1 비례 역치를 초과하는 경우, 상기 단말기에 의한 액세스 행위가 악의적인 액세스라고 판단하는 스텝을 포함하는 것을 특징으로 하는 유저 행위 식별 방법.
- 제1항에 있어서,
상기 시공간 슬라이딩 윈도우내의 액세스 행위에 근거하여 상기 시공간 슬라이딩 윈도우내의 액세스 행위를 평가하는 스텝은
상기 시공간 슬라이딩 윈도우중의 서로 인접하는 2개의 액세스 행위마다, 서로 인접하는 2개의 액세스 행위의 시간 간격을 취득하는 스텝과,
취득한 시간 간격에 근거하여 액세스 행위의 시간 분산을 산출하는 스텝과,
상기 시간 분산이 소정의 분산 역치를 초과하는지 여부를 판단하는 스텝
을 포함하고,
그 평가 결과에 근거하여 상기 단말기에 의한 액세스 행위가 악의적인 액세스인지를 판단하는 스텝은
상기 시간 분산이 소정의 분산 역치를 초과하는 경우, 상기 단말기에 의한 액세스 행위가 악의적인 액세스라고 판단하는 스텝을 포함하는 것을 특징으로 하는 유저 행위 식별 방법.
- 제1항에 있어서,
상기 시공간 슬라이딩 윈도우내의 액세스 행위에 근거하여 상기 시공간 슬라이딩 윈도우내의 액세스 행위를 평가하는 스텝은
상기 시공간 슬라이딩 윈도우중의 서로 인접하는 2개의 액세스 행위마다, 서로 인접하는 2개의 액세스 행위의 시간 간격을 취득하는 스텝과,
취득한 시간 간격에 근거하여 액세스 행위의 시간 분산을 산출하는 스텝과,
상기 시간 분산과 시간 간격의 평균치의 비율을 산출하는 스텝과,
상기 비율이 소정의 제2 비례 역치보다 작은지 여부를 판단하는 스텝
을 포함하고,
그 평가 결과에 근거하여 상기 단말기에 의한 액세스 행위가 악의적인 액세스인지를 판단하는 스텝은
상기 비율이 소정의 제2 비례 역치보다 작은 경우, 상기 단말기에 의한 액세스 행위가 악의적인 액세스라고 판단하는 스텝을 포함하는 것을 특징으로 하는 유저 행위 식별 방법.
- 제1항에 있어서,
상기 시공간 슬라이딩 윈도우내의 액세스 행위에 근거하여 상기 시공간 슬라이딩 윈도우내의 액세스 행위를 평가하는 스텝은
상기 시공간 슬라이딩 윈도우내의 액세스 행위의 총횟수를 취득하는 스텝과,
상기 총횟수가 소정의 총횟수 역치를 초과하는지 여부를 판단하는 스텝과,
그 판단 결과에 근거하여 상기 시공간 슬라이딩 윈도우내의 액세스 행위를 평가하는 스텝
을 포함하는 것을 특징으로 하는 유저 행위 식별 방법.
- 소정의 시공간 슬라이딩 윈도우내의 단말기에 의한 액세스 행위를 취득하기 위한 취득 모듈과,
상기 시공간 슬라이딩 윈도우내의 액세스 행위에 근거하여 상기 시공간 슬라이딩 윈도우내의 액세스 행위를 평가하기 위한 평가 모듈과,
그 평가 결과에 근거하여 상기 단말기에 의한 액세스 행위가 악의적인 액세스인지를 판단하기 위한 판단 모듈
을 포함하는 것을 특징으로 하는 유저 행위 식별 장치.
- 제6항에 있어서,
상기 시공간 슬라이딩 윈도우는 m개로 등분 된 타임 슬라이스를 포함하고,
상기 평가 모듈은
타임 슬라이스내의 액세스 횟수가 소정의 슬라이스 횟수 역치를 초과하는지를 타임 슬라이스마다 판단하여, 액세스 횟수가 소정의 슬라이스 횟수 역치를 초과하는 n개의 타임 슬라이스를 취득하기 위한 타임 슬라이스 서브모듈과,
n와 m의 비례가 소정의 제1 비례 역치를 초과하는지 여부를 판단하기 위한 제1 비례 서브모듈
을 포함하고,
상기 판단 모듈은
n와 m의 비례가 소정의 제1 비례 역치를 초과하는 경우, 상기 단말기에 의한 액세스 행위가 악의적인 액세스라고 판단하는 것을 특징으로 하는 유저 행위 식별 장치.
- 제6항에 있어서,
상기 평가 모듈은
상기 시공간 슬라이딩 윈도우중의 서로 인접하는 2개의 액세스 행위마다, 서로 인접하는 2개의 액세스 행위의 시간 간격을 취득하기 위한 간격 서브모듈과,
취득한 시간 간격에 근거하여 액세스 행위의 시간 분산을 산출하기 위한 분산 서브모듈과,
상기 시간 분산이 소정의 분산 역치를 초과하는지 여부를 판단하기 위한 제1 평가 서브모듈
을 포함하고,
상기 판단 모듈은
상기 시간 분산이 소정의 분산 역치를 초과하는 경우, 상기 단말기에 의한 액세스 행위가 악의적인 액세스라고 판단하는 것을 특징으로 하는 유저 행위 식별 장치.
- 제6항에 있어서,
상기 평가 모듈은
상기 시공간 슬라이딩 윈도우중의 서로 인접하는 2개의 액세스 행위마다, 서로 인접하는 2개의 액세스 행위의 시간 간격을 취득하기 위한 간격 서브모듈과,
취득한 시간 간격에 근거하여 액세스 행위의 시간 분산을 산출하기 위한 분산 서브모듈과,
상기 시간 분산과 시간 간격의 평균치의 비율을 산출하기 위한 비율 서브모듈과,
상기 비율이 소정의 제2 비례 역치보다 작은지 여부를 판단하기 위한 제2 비례 서브모듈
을 포함하고,
상기 판단 모듈은
상기 비율이 소정의 제2 비례 역치보다 작은 경우, 상기 단말기에 의한 액세스 행위가 악의적인 액세스라고 판단하는 것을 특징으로 하는 유저 행위 식별 장치.
- 제6항에 있어서,
상기 평가 모듈은
상기 시공간 슬라이딩 윈도우내의 액세스 행위의 총횟수를 취득하기 위한 총횟수 서브모듈과,
상기 총횟수가 소정의 총횟수 역치를 초과하는지 여부를 판단하기 위한 총횟수 판단 서브모듈과,
그 판단 결과에 근거하여 상기 시공간 슬라이딩 윈도우내의 액세스 행위를 평가하기 위한 제 2의 평가 서브모듈을 포함하는 것을 특징으로 하는 유저 행위 식별 장치.
- 프로세서와,
프로세서에 의해 실행 가능한 인스트럭션을 저장하기 위한 메모리
를 포함하는 유저 행위 식별 장치에 있어서,
상기 프로세서는
소정의 시공간 슬라이딩 윈도우내의 단말기에 의한 액세스 행위를 취득하고,
상기 시공간 슬라이딩 윈도우내의 액세스 행위에 근거하여 상기 시공간 슬라이딩 윈도우내의 액세스 행위를 평가하며,
그 평가 결과에 근거하여 상기 단말기에 의한 액세스 행위가 악의적인 액세스인지를 판단하도록 구성되는 것을 특징으로 하는 유저 행위 식별 장치.
Applications Claiming Priority (3)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201410708281.6A CN104486298B (zh) | 2014-11-27 | 2014-11-27 | 识别用户行为的方法及装置 |
| CN201410708281.6 | 2014-11-27 | ||
| PCT/CN2015/078019 WO2016082462A1 (zh) | 2014-11-27 | 2015-04-30 | 识别用户行为的方法及装置 |
Publications (2)
| Publication Number | Publication Date |
|---|---|
| KR20160077009A true KR20160077009A (ko) | 2016-07-01 |
| KR101677217B1 KR101677217B1 (ko) | 2016-11-17 |
Family
ID=52760802
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| KR1020157016876A Active KR101677217B1 (ko) | 2014-11-27 | 2015-04-30 | 유저 행위 식별 방법 및 유저 행위 식별 장치, 프로그램 및 저장매체 |
Country Status (9)
| Country | Link |
|---|---|
| US (1) | US20160156653A1 (ko) |
| EP (1) | EP3026864B1 (ko) |
| JP (1) | JP2017503293A (ko) |
| KR (1) | KR101677217B1 (ko) |
| CN (1) | CN104486298B (ko) |
| BR (1) | BR112015018912A2 (ko) |
| MX (1) | MX350670B (ko) |
| RU (1) | RU2628127C2 (ko) |
| WO (1) | WO2016082462A1 (ko) |
Cited By (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| KR102034998B1 (ko) * | 2019-07-12 | 2019-10-22 | 경상대학교산학협력단 | 돼지움직임 감지용 광이표 |
| KR20210007613A (ko) * | 2019-07-12 | 2021-01-20 | 경상대학교산학협력단 | 가속도 센서를 구비한 돼지이표 |
| US11240258B2 (en) | 2015-11-19 | 2022-02-01 | Alibaba Group Holding Limited | Method and apparatus for identifying network attacks |
Families Citing this family (20)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN104486298B (zh) * | 2014-11-27 | 2018-03-09 | 小米科技有限责任公司 | 识别用户行为的方法及装置 |
| CN104881479B (zh) * | 2015-06-03 | 2018-07-13 | 北京京东尚科信息技术有限公司 | 一种限制用户最小操作间隔的方法及装置 |
| CN106327230B (zh) * | 2015-06-30 | 2019-12-24 | 阿里巴巴集团控股有限公司 | 一种异常用户检测方法及设备 |
| CN104967629B (zh) * | 2015-07-16 | 2018-11-27 | 网宿科技股份有限公司 | 网络攻击检测方法及装置 |
| CN105282047B (zh) * | 2015-09-25 | 2020-04-14 | 小米科技有限责任公司 | 访问请求处理方法及装置 |
| CN111629010B (zh) * | 2015-11-23 | 2023-03-10 | 创新先进技术有限公司 | 一种恶意用户识别方法及装置 |
| EP4102437A1 (en) * | 2016-03-04 | 2022-12-14 | Axon Vibe AG | Systems and methods for predicting user behavior based on location data |
| CN106506451B (zh) * | 2016-09-30 | 2019-08-27 | 百度在线网络技术(北京)有限公司 | 恶意访问的处理方法及装置 |
| JP6737189B2 (ja) * | 2017-01-18 | 2020-08-05 | トヨタ自動車株式会社 | 不正判定システム及び不正判定方法 |
| CN106657410B (zh) * | 2017-02-28 | 2018-04-03 | 国家电网公司 | 基于用户访问序列的异常行为检测方法 |
| CN107046489B (zh) * | 2017-04-07 | 2020-07-28 | 上海熙菱信息技术有限公司 | 一种频次类实时统计模型系统及方法 |
| CN107481090A (zh) * | 2017-07-06 | 2017-12-15 | 众安信息技术服务有限公司 | 一种用户异常行为检测方法、装置和系统 |
| FR3094518B1 (fr) | 2019-04-01 | 2021-02-26 | Idemia Identity & Security France | Procédé de détection de bots dans un réseau d’utilisateurs |
| CN111224939B (zh) * | 2019-11-15 | 2022-07-12 | 上海钧正网络科技有限公司 | 任务请求的拦截方法、装置、计算机设备和存储介质 |
| CN110933115B (zh) * | 2019-12-31 | 2022-04-29 | 上海观安信息技术股份有限公司 | 基于动态session的分析对象行为异常检测方法及装置 |
| CN113114611B (zh) * | 2020-01-13 | 2024-02-06 | 北京沃东天骏信息技术有限公司 | 黑名单管理的方法和装置 |
| CN112784288B (zh) * | 2021-01-22 | 2024-05-10 | 尚娱软件(深圳)有限公司 | 访问管理方法、终端及计算机可读存储介质 |
| US11991196B2 (en) | 2021-03-04 | 2024-05-21 | Qatar Foundation For Education, Science And Community Development | Anomalous user account detection systems and methods |
| CN113553528B (zh) * | 2021-07-23 | 2024-12-13 | 咪咕文化科技有限公司 | 业务访问频率控制方法、装置、计算设备和存储介质 |
| US12481758B2 (en) * | 2022-09-29 | 2025-11-25 | Mcafee, Llc | Methods and apparatus to disable select processes for malware prevention |
Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| KR20040057177A (ko) * | 2002-12-24 | 2004-07-02 | 한국전자통신연구원 | 슬라이딩 윈도우 캐쉬 구조와 이를 이용한 네트워크공격상황의 데이터 기록 및 분석 방법 |
| KR20060025871A (ko) * | 2004-09-17 | 2006-03-22 | 주식회사 케이티 | 가상 웹서버 기반의 침입 유도 시스템 및 그 방법 |
| EP2009864A1 (en) * | 2007-06-28 | 2008-12-31 | Nibelung Security Systems GmbH | Method and apparatus for attack prevention |
Family Cites Families (23)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2000148276A (ja) * | 1998-11-05 | 2000-05-26 | Fujitsu Ltd | セキュリティ監視装置,セキュリティ監視方法およびセキュリティ監視用プログラム記録媒体 |
| JP2005044277A (ja) * | 2003-07-25 | 2005-02-17 | Fuji Xerox Co Ltd | 不正通信検出装置 |
| JP2006279930A (ja) * | 2005-03-01 | 2006-10-12 | Nec Corp | 不正アクセス検出方法及び装置、並びに不正アクセス遮断方法及び装置 |
| RU2460220C2 (ru) * | 2007-01-16 | 2012-08-27 | Абсолют Софтвеа Корпорейшн | Модуль обеспечения безопасности, включающий вторичный агент, взаимодействующий с главным агентом |
| US7885976B2 (en) * | 2007-02-23 | 2011-02-08 | International Business Machines Corporation | Identification, notification, and control of data access quantity and patterns |
| JP4948359B2 (ja) * | 2007-10-26 | 2012-06-06 | 三菱電機株式会社 | 不正アクセス検知装置及び不正アクセス検知方法及びプログラム |
| US20090144545A1 (en) * | 2007-11-29 | 2009-06-04 | International Business Machines Corporation | Computer system security using file system access pattern heuristics |
| JP2009217555A (ja) * | 2008-03-11 | 2009-09-24 | Mitsubishi Electric Corp | ネットワーク異常判定装置 |
| US8326987B2 (en) * | 2008-11-12 | 2012-12-04 | Lin Yeejang James | Method for adaptively building a baseline behavior model |
| US8572736B2 (en) * | 2008-11-12 | 2013-10-29 | YeeJang James Lin | System and method for detecting behavior anomaly in information access |
| CN101446956A (zh) * | 2008-12-12 | 2009-06-03 | 北京理工大学 | 预测模型的在线增量式插入与删除方法 |
| JP2010146160A (ja) * | 2008-12-17 | 2010-07-01 | Kureo:Kk | 通信管理装置、通信管理方法、およびプログラム |
| WO2010088550A2 (en) * | 2009-01-29 | 2010-08-05 | Breach Security, Inc. | A method and apparatus for excessive access rate detection |
| US9805271B2 (en) * | 2009-08-18 | 2017-10-31 | Omni Ai, Inc. | Scene preset identification using quadtree decomposition analysis |
| JP5911431B2 (ja) * | 2010-01-21 | 2016-05-11 | アリババ・グループ・ホールディング・リミテッドAlibaba Group Holding Limited | 悪意のあるアクセスの遮断 |
| CN102769549B (zh) * | 2011-05-05 | 2016-02-17 | 腾讯科技(深圳)有限公司 | 网络安全监控的方法和装置 |
| US9571508B2 (en) * | 2011-07-29 | 2017-02-14 | Hewlett Packard Enterprise Development Lp | Systems and methods for distributed rule-based correlation of events |
| JP5791548B2 (ja) * | 2012-03-15 | 2015-10-07 | 三菱電機株式会社 | アドレス抽出装置 |
| US20130291107A1 (en) * | 2012-04-27 | 2013-10-31 | The Irc Company, Inc. | System and Method for Mitigating Application Layer Distributed Denial of Service Attacks Using Human Behavior Analysis |
| US20140304833A1 (en) * | 2013-04-04 | 2014-10-09 | Xerox Corporation | Method and system for providing access to crowdsourcing tasks |
| CN104113519B (zh) * | 2013-04-16 | 2017-07-14 | 阿里巴巴集团控股有限公司 | 网络攻击检测方法及其装置 |
| RU133954U1 (ru) * | 2013-04-29 | 2013-10-27 | Федеральное государственное образовательное бюджетное учреждение высшего профессионального образования "Санкт-Петербургский государственный университет телекоммуникаций им. проф. М.А. Бонч-Бруевича" (СПбГУТ) | Устройство защиты сети |
| CN104486298B (zh) * | 2014-11-27 | 2018-03-09 | 小米科技有限责任公司 | 识别用户行为的方法及装置 |
-
2014
- 2014-11-27 CN CN201410708281.6A patent/CN104486298B/zh active Active
-
2015
- 2015-04-30 JP JP2016561070A patent/JP2017503293A/ja active Pending
- 2015-04-30 MX MX2015009131A patent/MX350670B/es active IP Right Grant
- 2015-04-30 RU RU2015128769A patent/RU2628127C2/ru active
- 2015-04-30 WO PCT/CN2015/078019 patent/WO2016082462A1/zh not_active Ceased
- 2015-04-30 KR KR1020157016876A patent/KR101677217B1/ko active Active
- 2015-04-30 BR BR112015018912A patent/BR112015018912A2/pt not_active IP Right Cessation
- 2015-11-05 US US14/933,197 patent/US20160156653A1/en not_active Abandoned
- 2015-11-24 EP EP15196035.8A patent/EP3026864B1/en active Active
Patent Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| KR20040057177A (ko) * | 2002-12-24 | 2004-07-02 | 한국전자통신연구원 | 슬라이딩 윈도우 캐쉬 구조와 이를 이용한 네트워크공격상황의 데이터 기록 및 분석 방법 |
| KR20060025871A (ko) * | 2004-09-17 | 2006-03-22 | 주식회사 케이티 | 가상 웹서버 기반의 침입 유도 시스템 및 그 방법 |
| EP2009864A1 (en) * | 2007-06-28 | 2008-12-31 | Nibelung Security Systems GmbH | Method and apparatus for attack prevention |
Cited By (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US11240258B2 (en) | 2015-11-19 | 2022-02-01 | Alibaba Group Holding Limited | Method and apparatus for identifying network attacks |
| KR102034998B1 (ko) * | 2019-07-12 | 2019-10-22 | 경상대학교산학협력단 | 돼지움직임 감지용 광이표 |
| KR20210007613A (ko) * | 2019-07-12 | 2021-01-20 | 경상대학교산학협력단 | 가속도 센서를 구비한 돼지이표 |
Also Published As
| Publication number | Publication date |
|---|---|
| MX2015009131A (es) | 2016-08-01 |
| KR101677217B1 (ko) | 2016-11-17 |
| BR112015018912A2 (pt) | 2017-07-18 |
| MX350670B (es) | 2017-09-12 |
| WO2016082462A1 (zh) | 2016-06-02 |
| US20160156653A1 (en) | 2016-06-02 |
| CN104486298B (zh) | 2018-03-09 |
| RU2015128769A (ru) | 2017-01-20 |
| EP3026864A1 (en) | 2016-06-01 |
| JP2017503293A (ja) | 2017-01-26 |
| RU2628127C2 (ru) | 2017-08-15 |
| CN104486298A (zh) | 2015-04-01 |
| EP3026864B1 (en) | 2018-09-26 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| KR101677217B1 (ko) | 유저 행위 식별 방법 및 유저 행위 식별 장치, 프로그램 및 저장매체 | |
| CN109831465B (zh) | 一种基于大数据日志分析的网站入侵检测方法 | |
| US9462009B1 (en) | Detecting risky domains | |
| CN104391979B (zh) | 网络恶意爬虫识别方法及装置 | |
| CN103701795B (zh) | 拒绝服务攻击的攻击源的识别方法和装置 | |
| Viswanath et al. | Towards detecting anomalous user behavior in online social networks | |
| US10938844B2 (en) | Providing security through characterizing mobile traffic by domain names | |
| US20180295149A1 (en) | System and method for detecting directed cyber-attacks targeting a particular set of cloud based machines | |
| US9621576B1 (en) | Detecting malicious websites | |
| US11588851B2 (en) | Detecting device masquerading in application programming interface (API) transactions | |
| CN109302423B (zh) | 一种漏洞扫描能力测试方法和装置 | |
| CN107465648A (zh) | 异常设备的识别方法及装置 | |
| KR101731312B1 (ko) | 사용자 단말의 애플리케이션에 대한 권한변경 탐지 방법, 장치 및 컴퓨터 판독가능 기록매체 | |
| CN113765850B (zh) | 物联网异常检测方法、装置、计算设备及计算机存储介质 | |
| Heid et al. | Haven't we met before?-Detecting Device Fingerprinting Activity on Android Apps | |
| CN107426136B (zh) | 一种网络攻击的识别方法和装置 | |
| Van Goethem et al. | One {Side-Channel} to Bring Them All and in the Darkness Bind Them: Associating Isolated Browsing Sessions | |
| CN115190108B (zh) | 一种检测被监控设备的方法、装置、介质及电子设备 | |
| KR20150133370A (ko) | 웹서비스 접속제어 시스템 및 방법 | |
| US9118563B2 (en) | Methods and apparatus for detecting and filtering forced traffic data from network data | |
| KR102040227B1 (ko) | 장치 간 보안 유효성을 평가하는 방법 및 시스템 | |
| KR102233525B1 (ko) | 페이지 리다이렉트 루프를 검출하기 위한 방법 및 장치 | |
| CN113553589B (zh) | 恶意软件传播特征的提取方法、装置和应用 | |
| KR20150088047A (ko) | 접속시간 기준 평판생성 방법, 그리고 이를 이용한 DDoS 방어 방법 및 시스템 | |
| CN112751828A (zh) | 对网络攻击事件的损失评估方法、装置和电子设备 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| A201 | Request for examination | ||
| PA0105 | International application |
Patent event date: 20150624 Patent event code: PA01051R01D Comment text: International Patent Application |
|
| PA0201 | Request for examination |
Patent event code: PA02012R01D Patent event date: 20150624 Comment text: Request for Examination of Application |
|
| E902 | Notification of reason for refusal | ||
| PE0902 | Notice of grounds for rejection |
Comment text: Notification of reason for refusal Patent event date: 20160503 Patent event code: PE09021S01D |
|
| PG1501 | Laying open of application | ||
| E701 | Decision to grant or registration of patent right | ||
| PE0701 | Decision of registration |
Patent event code: PE07011S01D Comment text: Decision to Grant Registration Patent event date: 20161026 |
|
| GRNT | Written decision to grant | ||
| PR0701 | Registration of establishment |
Comment text: Registration of Establishment Patent event date: 20161111 Patent event code: PR07011E01D |
|
| PR1002 | Payment of registration fee |
Payment date: 20161114 End annual number: 3 Start annual number: 1 |
|
| PG1601 | Publication of registration | ||
| FPAY | Annual fee payment |
Payment date: 20191101 Year of fee payment: 4 |
|
| PR1001 | Payment of annual fee |
Payment date: 20191101 Start annual number: 4 End annual number: 4 |
|
| FPAY | Annual fee payment |
Payment date: 20201030 Year of fee payment: 5 |
|
| PR1001 | Payment of annual fee |
Payment date: 20201030 Start annual number: 5 End annual number: 5 |
|
| FPAY | Annual fee payment |
Payment date: 20211029 Year of fee payment: 6 |
|
| PR1001 | Payment of annual fee |
Payment date: 20211029 Start annual number: 6 End annual number: 6 |
|
| FPAY | Annual fee payment |
Payment date: 20221104 Year of fee payment: 7 |
|
| PR1001 | Payment of annual fee |
Payment date: 20221104 Start annual number: 7 End annual number: 7 |
