Patent9 专利在线
高级搜索 ▼
申请号或专利号
公开号
专利名称
专利摘要
申请人
发明人
全部专利
发明专利
实用新型专利
外观设计专利
高级搜索 - 多字段组合检索
+ 增加条件
查询语句:
(请输入搜索条件)
普通搜索
当前查询到
1
条专利与查询词 "
MIERALIMUJIANG TUERHONG
"相关,搜索用时0.5312487秒!
排序方式:
按相关度排序
按申请日升序↑
按申请日降序↓
按公开日升序↑
按公开日降序↓
发明专利:
1
实用新型:
0
外观设计:
0
共
1
条,当前第
1-1
条
返回搜索页
1:
[发明]
【中文】终端取证溯源系统及方法 【EN】Terminal evidence obtaining and tracing system and method
申请号:
201911276014.5
公开号:CN110990830A 主分类号:G06F21/55
申请人:
【中文】国网新疆电力有限公司信息通信公司
;
国家电网有限公司【EN】INFORMATION COMMUNICATION COMPANY, STATE GRID XINJIANG ELECTRIC POWER Co.
;
STATE GRID CORPORATION OF CHINA
申请日:2019.12.12 公开日:2020.04.10
发明人:
【中文】黄强
;
何伟
;
运凯
;
李凯
;
米尔阿力木江·吐尔洪
;
李浩升
;
鲁学仲
;
曹澍
;
王庆鹏
;
马怡璇
;
赵梅
;
康婉晴【EN】Huang Qiang
;
He Wei
;
Yunkai
;
Li Kai
;
MIERALIMUJIANG TUERHONG
;
Li Haosheng
;
Lu Xuezhong
;
Cao Shu
;
Wang Qingpeng
;
Ma Yixuan
;
Zhao Mei
;
Kang Wanqing
摘要:【中文】本发明涉及一种网络攻击技术领域,是一种终端取证溯源系统及方法,前者包括终端数据采集单元、分析处理单元和报告生成单元;终端数据采集单元,基于攻击者视角的攻击链,对目标终端进行全方位扫描取证,采集需要的所有业务数据;分析处理单元,通过识别溯源工具对采集到的所有业务数据进行检测判定及处理研判;报告生成单元,根据检测判定结果、处理结果生成取证分析报告。本发明集采集、分析、处理于一体,能自动完成终端的取证追溯过程,并形成取证分析报告,简化了终端取证追溯工作,降低了对运维人员的要求,同时能通过前端显示单元对溯源工具进行更新及添加,有效增加了恶意活动等攻击、威胁的识别及溯源。 【EN】The invention relates to the technical field of network attack, in particular to a terminal evidence obtaining and tracing system and a method, wherein the terminal evidence obtaining and tracing system comprises a terminal data acquisition unit, an analysis processing unit and a report generating unit; the terminal data acquisition unit is used for carrying out all-dimensional scanning evidence obtaining on the target terminal based on an attack chain of an attacker view angle and acquiring all required service data; the analysis processing unit is used for detecting, judging, processing and studying all the collected business data through the identification traceability tool; and a report generation unit for generating an evidence collection analysis report according to the detection judgment result and the processing result. The invention integrates acquisition, analysis and processing, can automatically finish the evidence obtaining and tracing process of the terminal, forms an evidence obtaining and analyzing report, simplifies the evidence obtaining and tracing work of the terminal, reduces the requirements on operation and maintenance personnel, can update and add tracing tools through the front-end display unit, and effectively increases the identification and tracing of attacks and threats such as malicious activities.
详细信息
下载全文
共
1
条,当前第
1-1
条
返回搜索页