FIELD: computer technology.
SUBSTANCE: invention relates to a method and system for preventing malicious automated attacks. In the method, the user is evaluated based on the received request to the computer system about the session, collecting numerical and statistical metrics of the request, counting metrics that characterize the user based on statistics of their communication with the resource, determining metrics based on general statistics on the resource showing the deviation of the user’s session from the median and average session, based on these data, an assessment of the legitimacy of the request is obtained through a statistical model, on the basis of which the user is assigned to one of the categories: legitimate, suspicious or bot, for a legitimate user, access to a resource is provided, blocked to a resource for a bot, and additional verification is performed against a suspicious user, while on the basis of an analysis of their behavior, the user is offered a task using cryptographic algorithms using asymmetric encryption, in the absence of a correct solution to the problem, they are determine as a bot and access to the resource is blocked, in the case of a correct solution, they are determine as a legitimate user and access is provided.
EFFECT: ensuring the prevention of malicious attacks.
14 cl, 3 dwg
Title | Year | Author | Number |
---|---|---|---|
METHOD AND SYSTEM FOR PREVENTING MALICIOUS AUTOMATED ATTACKS | 2020 |
|
RU2740027C1 |
INTELLIGENT BOTS DETECTION AND PROTECTION SYSTEM AND METHOD | 2020 |
|
RU2738337C1 |
SYSTEM AND METHOD FOR AUTOMATIC ASSESSMENT OF QUALITY OF NETWORK TRAFFIC SIGNATURES | 2021 |
|
RU2781822C1 |
SYSTEM AND METHOD OF REDUCING FALSE RESPONSES WHEN DETECTING NETWORK ATTACK | 2011 |
|
RU2480937C2 |
METHOD OF CONSTRUCTING DATA NETWORKS WITH HIGH LEVEL OF SECURITY FROM DDoS ATTACKS | 2015 |
|
RU2576488C1 |
SYSTEM AND METHOD FOR DETECTION OF TARGET ATTACKS | 2014 |
|
RU2601147C2 |
SYSTEM AND METHOD OF DETERMINATION OF DDOS-ATTACKS UNDER FAILURE OF SERVICE SERVERS | 2017 |
|
RU2665919C1 |
DDoS-ATTACKS DETECTION SYSTEM AND METHOD | 2017 |
|
RU2676021C1 |
SYSTEM AND METHOD OF SETTING SECURITY SYSTEMS UNDER DDOS ATTACKS | 2017 |
|
RU2659735C1 |
ARTIFICIAL INTELLIGENCE BASED COMPUTER SECURITY SYSTEM | 2017 |
|
RU2750554C2 |
Authors
Dates
2022-03-24—Published
2021-02-10—Filed