Research on High Suspicious IP Detection Technology Based on Multi source Heterogeneous Data

J. B. Liu, Fei Wang, Ming Yan · 2024

As the competition against cyber attacks becomes increasingly fierce, cyber attacks are gradually developing towards dynamism, sophistication, concealment, multi-step, coordination, distribution, and directionality. In response to the current situation where key information infrastructure units rely on single security device detection capabilities, lack security data linkage analysis, and insufficient personnel security modeling capabilities when conducting threat detection, this article uses big data analysis technology to discover and warn of network security events through data mining, multi-source heterogeneous data normalization analysis, user abnormal behavior analysis, and other techniques. A prototype system has been implemented and applied in typical environments for verification, which can effectively reduce the impact of network security "noise" data, carry out multi-dimensional security data correlation analysis, and improve the ability of key information infrastructure units to quickly detect, warn, locate, and dispose of network security threats.

Read the paper · More papers on PaperTik