ID |
原文 |
译文 |
44536 |
日益增长的网络流量使得有效识别恶意访问成为亟待解决的网络安全问题之一, |
The growing network traffic makes effective identification of malicious access one of the network security issues that need to be addressed. |
44537 |
现有的检测方法多是基于域名黑名单展开研究的,忽略了非黑名单中也可能存在着隐藏的恶意访问。 |
Most of the existing detection methods are based on the domain name blacklist, ignoring the hidden malicious access in the non-blacklist. |
44538 |
为了解决上述问题,利用了时间序列的分析方法建立了一种基于 URL 的恶意访问检测模型。 |
In order to solve the above problems, a URL-based malicious access detection model by using time series analysis method was proposed. |
44539 |
首先,以用户访问某域名的 URL 日志为研究对象,从域名访问相似度、信息熵、功率谱密度等多维度挖掘恶意访问的表现特征, |
Firstly, the performance was studied and quantified characteristics of malicious access from multiple dimensions by the user accessing the URL log of a domain name, such as domain name access similarity, information entropy and power spectral density. |
44540 |
然后结合混合高斯聚类算法给出基于URL 的恶意访问检测模型。 |
Then a malicious access detection model combined was generated with the Gaussian clustering algorithm. |
44541 |
实验结果表明,该模型具有较高的准确率。 |
The experimental results show that the proposed model has higher accuracy. |
44542 |
通过设计和搭建推广感染检测系统,对教育网 edu.cn 域名及教育部备案的中小学域名进行了测量。 |
Through the design and construction of the promotional infection detecting system, the CERNET edu.cn do-main names and the primary & secondary school domain names filed by the Ministry of Education were measured. |
44543 |
经过对测量结果的分析,发现有 4.68%的高校域名及 2.75%的中小学域名下存在推广感染,同时分析了推广感染页面的行为特征,检测出在高校和中小学站点中分别有 39.5%和 20.7%的推广感染页面存在伪装或引流行为。 |
After analyzing the measurement results, it was found that there were 4.68% of university domain names and 2.75% of primary and secondary school domain names were infected, and after analyzing the behavioral characteristics of the promotional infection pages, detecting 39.5% promotional infection pages on edu.cn websites and 20.7% on primary & secondary school websites have cloaking or redirecting behaviors. |
44544 |
这些测量结果揭示了教育类官网当前所面临的内容被篡改和植入的问题。 |
These measurements reveal the problems that the current content of the education official website has been tampered with and implanted. |
44545 |
此外,使用的测量方法也可以协助运维人员进行自身网站的推广感染检测。 |
In addition, the measurement method used can also assist the operation and maintenance personnel to carry out the promotion of infection detection on their own websites. |