朱京毅, 罗汉斌. Research on threat detection based on dynamic behavior and network traffic analysis technology[J]. 2020, 33(12): 25-29. DOI: 10.13992/j.cnki.tetas.2020.12.005.
基于动态行为与网络流量分析技术的威胁检测研究
摘要
随着网络技术的快速发展
伴随而来的是愈来愈多的新型网络威胁
传统安全防护体系也濒临失效
基于全流量威胁检测逐渐成为新型威胁检测的有效途径。在实战过程中
依靠传统的分析方式
传统安全设备通常无法对新型网络威胁的各个阶段进行有效的检测。换个角度来看攻防实战
真相往往隐藏在网络流量中。本文采用网络流量实时采集的思路
通过动态行为分析和网络流量分析技术实现新型网络威胁行为检测
有效解决了新型网络威胁的发现难题。
Abstract
With the rapid development of network technology
there are more and more new network threats. Traditional security protection systems are also on the verge of failure. Threat detection based on full traffic has gradually become an effective way to detect new threats. In the actual combat process
relying on traditional analysis methods
traditional security equipment usually cannot effectively detect the various stages of new cyber threats. Looking at the actual attack and defense from another angle
the truth is often hidden in the network traffic. This article uses real-time network traffic collection. The idea of using dynamic behavior analysis and network traffic analysis technology to achieve new network threat behavior detection
effectively solve the problem of new network threat discovery.