FIELD: physics.
SUBSTANCE: invention relates to a method and a system for preventing malicious automated attacks. Method comprises evaluating user based on obtained request to computer system on session, performing collection of numerical and statistical metrics of request, count of metrics that characterize user based on statistics of its communication with resource, determination of metrics based on common statistics on resource, indicating deviation of user session from median and middle session, on the basis of these data, evaluation of legitimacy of request by means of statistical model, based on which user is determined to one of categories of legitimate, suspicious or bot, for legitimate user is granted access to resource, for a bot - blocking access to a resource, performing additional checking with respect to a suspicious user, while on the basis of analysing its behaviour, it is presented with a task using cryptographic algorithms using asymmetric encryption, in case of absence of the correct solution of the task, it is defined as a bot and blocked access to the resource; in case of the correct solution, it is identified as a legitimate user and access is granted.
EFFECT: technical result is to ensure prevention of malicious attacks.
14 cl, 3 dwg
Title | Year | Author | Number |
---|---|---|---|
METHOD AND SYSTEM FOR PREVENTING MALICIOUS AUTOMATED ATTACKS | 2021 |
|
RU2768567C1 |
INTELLIGENT BOTS DETECTION AND PROTECTION SYSTEM AND METHOD | 2020 |
|
RU2738337C1 |
SYSTEM AND METHOD FOR AUTOMATIC ASSESSMENT OF QUALITY OF NETWORK TRAFFIC SIGNATURES | 2021 |
|
RU2781822C1 |
SYSTEM AND METHOD OF REDUCING FALSE RESPONSES WHEN DETECTING NETWORK ATTACK | 2011 |
|
RU2480937C2 |
METHOD OF CONSTRUCTING DATA NETWORKS WITH HIGH LEVEL OF SECURITY FROM DDoS ATTACKS | 2015 |
|
RU2576488C1 |
SYSTEM AND METHOD FOR DETECTION OF TARGET ATTACKS | 2014 |
|
RU2601147C2 |
SYSTEM AND METHOD OF DETERMINATION OF DDOS-ATTACKS UNDER FAILURE OF SERVICE SERVERS | 2017 |
|
RU2665919C1 |
DDoS-ATTACKS DETECTION SYSTEM AND METHOD | 2017 |
|
RU2676021C1 |
SYSTEM AND METHOD OF SETTING SECURITY SYSTEMS UNDER DDOS ATTACKS | 2017 |
|
RU2659735C1 |
ARTIFICIAL INTELLIGENCE BASED COMPUTER SECURITY SYSTEM | 2017 |
|
RU2750554C2 |
Authors
Dates
2020-12-30—Published
2020-02-12—Filed