Method and device for recognizing an IP address of a specified category, a defense method and system

US10033694B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10033694-B2
Application numberUS-201415033202-A
CountryUS
Kind codeB2
Filing dateAug 18, 2014
Priority dateNov 1, 2013
Publication dateJul 24, 2018
Grant dateJul 24, 2018

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

The invention discloses a method and device for recognizing an IP address of a specified category, a defense method and system, wherein the method for recognizing an IP address of a specified category comprises the following steps: collecting behavior record data of several IP addresses (S 101 ); extracting preprocessing data from the collected behavior record data, the extracted preprocessing data comprising at least address information of an IP address and time information of a behavior (S 102 ); analyzing the extracted preprocessing data to obtain behavior-time distribution data of a user using the IP address (S 103 ); and recognizing an IP address of a specified category at least according to the behavior-time distribution data of a user using the IP address (S 104 ). By employing the invention, an IP address of a certain category can be located more accurately locate and the accuracy for recognizing an IP address is improved.

First claim

Opening claim text (preview).

The invention claimed is: 1. A computer-implemented method for recognizing an IP address of a specified category, comprising: collecting, by at least one processor of a computer system, behavior record data of several IP addresses; extracting, by the at least one processor, preprocessing data from the collected behavior record data, the extracted preprocessing data comprising at least address information of an IP address and time information of a behavior; analyzing, by the at least one processor, the extracted preprocessing data to obtain behavior-time distribution data of a user using the IP address; and recognizing, by the at least one processor, the IP address of a specified category at least according to the behavior-time distribution data of the user using the IP address, wherein the recognizing the IP address of the specified category further comprises: performing, by the at least one processor, clustering on the several IP addresses by combining one or more kinds of clustering modes based on the behavior-time distribution data of each IP address to recognize the IP address of the specified category, wherein the performing clustering further comprises: selecting, by the at least one processor and from the collected several IP addresses, at least two IP addresses known to belong to different categories as initial nodes of a first clustering mode; based on the behavior-time distribution data of each IP address and the behavior-time distribution data of the initial nodes, performing, by the at least one processor, clustering on the collected several IP addresses by employing the first clustering mode to recognize multiple IP addresses of the specified category; performing, by the at least one processor, sampling cluster analysis on the recognized multiple IP addresses of the specified category by employing a second clustering mode to obtain data distribution characteristics of the specified category; modifying, by the at least one processor, the initial nodes of the first clustering mode according to the data distribution characteristics obtained by employing the second clustering mode; and adopting the modified initial nodes to perform clustering on the recognized multiple IP addresses of the specified category by employing the first clustering mode to screen out IP addresses of the specified category. 2. The computer-implemented method as claimed in claim 1 , wherein the first clustering mode employs a Kmeans algorithm, and the second clustering mode employs a DBScan algorithm. 3. The computer-implemented method as claimed in claim 1 , wherein the extracted preprocessing data further comprises a number of user terminals and user terminal identifications corresponding to each IP address, and the analyzing the extracted preprocessing data comprises: counting, by the at least one processor, a number of user terminals corresponding to each IP address; dividing, by the at least one processor, preprocessing data of each IP address of which the number of user terminals is greater than a threshold into multiple dimensions according to a difference of behavior time, and counting a number of user terminals using each IP address in a different period of time; and performing, by the at least one processor, normalization processing on the number of user terminals using each IP address in different periods of time to obtain the behavior-time distribution data of the user using the IP address. 4. A computer-implemented method for improving security defense of a user terminal, comprising: recognizing, by the at least one processor, IP addresses of the specified category by the method for recognizing the IP address of the specified category as claimed in claim 1 ; monitoring, by the at least one processor, information security condition and IP address of each user terminal; detecting, by the at least one processor, a malicious program in a user terminal having an IP address belonging to the specified category; and improving, by the at least one processor, security defense level or performing special security defense processing. 5. A device for recognizing an IP address of a specified category comprising: a first non-transitory memory having first instructions stored thereon; a first processor configured to execute the first instructions to perform at least: collecting behavior record data of several IP addresses; extracting preprocessing data from the collected behavior record data, the extracted preprocessing data comprising at least address information of an IP address and time information of a behavior; analyzing the extracted preprocessing data to obtain behavior-time distribution data of a user using the IP address; and recognizing the IP address of the specified category at least according to the behavior-time distribution data of the user using the IP address, wherein recognizing the IP address of the specified category further comprises: performing cluster analysis on the several IP addresses by combining one or more kinds of clustering mode based on the behavior-time distribution data of each IP address to recognize the IP address of the specified category, wherein the performing the cluster analysis further comprises: selecting, from the collected several IP addresses, at least two IP addresses known to belong to different categories as initial nodes of a first clustering mode; based on the behavior-time distribution data of each IP address and the behavior-time distribution data of the initial nodes, performing clustering on the collected several IP addresses by employing the first clustering mode to recognize multiple IP addresses of the specified category; performing sampling cluster analysis on the recognized multiple IP addresses of the specified category by employing a second clustering mode to obtain data distribution characteristics of the specified category; and modifying the initial nodes of the first clustering mode according to the data distribution characteristics obtained by employing the second clustering mode; and adopting the modified initial nodes to perform clustering on the recognized multiple IP addresses of the specified category by employing the first clustering mode to screen out IP addresses of the specified category. 6. A system for improving security defense of a user terminal comprising: a recognition device for recognizing the IP address of the specified category as claimed in claim 5 , and further comprising: a second non-transitory memory having second instructions stored thereon; a second processor configured to execute the second instructions to perform at least: monitoring information security condition and IP address of each user terminal; detecting a malicious program in a user terminal corresponding to the IP address of the specified category recognized by the recognition device; improving security defense level or performing special security defense processing. 7. A non-transitory computer readable medium having instructions stored thereon that, when executed by at least one processor, cause the at least one processor to perform at least: collecting behavior record data of several IP addresses; extracting preprocessing data from the collected behavior record data, the extracted preprocessing data comprising at least address information of an IP address and time information of a behavior; analyzing the extracted preprocessing data to obtain behavior-time distribution data of a user using the IP address; and recognizing the IP address of a specified category at least according to the behavior-time distribution data of the user using the IP address, wherein recognizing the IP address of the specified category further comprise: performing, by the at least one processor, cluster analysis on the

Assignees

Inventors

Classifications

  • Electricity · mapped topic

  • Traffic logging, e.g. anomaly detection · CPC title

  • Filtering by address, protocol, port number or service, e.g. IP-address or URL · CPC title

  • Rule management · CPC title

  • Tracking the activity of the user (network monitoring arrangements H04L43/00; recording of computer activity G06F11/34) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10033694B2 cover?
The invention discloses a method and device for recognizing an IP address of a specified category, a defense method and system, wherein the method for recognizing an IP address of a specified category comprises the following steps: collecting behavior record data of several IP addresses (S 101 ); extracting preprocessing data from the collected behavior record data, the extracted preprocessing …
Who is the assignee on this patent?
Beijing Qihoo Technology Co
What technology area does this patent fall under?
Primary CPC classification H04L63/0236. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Jul 24 2018 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).