白丝美女被狂躁免费视频网站,500av导航大全精品,yw.193.cnc爆乳尤物未满,97se亚洲综合色区,аⅴ天堂中文在线网官网

Method for HTTP-based access point fingerprint and classification using machine learning

專利號
US11399288B2
公開日期
2022-07-26
申請人
SAMSUNG ELETR?NICA DA AMAZ?NIA LTDA.(BR Campinas)
發(fā)明人
Igor Jochem Sanz
IPC分類
H04W12/122; G06N20/20; H04L9/40; H04W12/60; H04W12/79
技術(shù)領(lǐng)域
http,ap,packet,html,captive,header,server,malicious,phishing,portal
地域: S?o Paulo

摘要

A method for HyperText Transfer Protocol (HTTP) based fingerprint and classification. The method includes training a HTTP-based machine-learning model, using machine-learning training techniques and a historical dataset of labelled Access Point HTTP service response features collected. The method is useful to detect benign or malicious classes, to assess the potential trustworthiness, to detect any type of bad behavior of an HTTP server, and any other threats that modify or implement an AP HTTP server or webpage. The method takes advantage of the captive portal detection packet exchange between a station and an Access Point (AP) to passively classify the AP.

說明書

The technique proposed by the present invention is stealth, since it makes advantage of the captive portal detection packet exchange between a station and an Access Point to passively classify the AP. The present invention begins with a captive portal detection packet exchange event, which occurs when a station connects to an AP and is checking Internet connectivity of the AP to verify if AP contains a captive portal. Internet connectivity is verified by sending an HTTP request packet (usually a request with code 204) to a known IP domain, in which response is known and comparing the AP response with the expected response (usually a “no content” packet). In general, if response is different from expected, devices trigger captive portal and display a webpage that is delivered by the Access Point to the user. The present invention is executed passively during the beginning of the AP connection. However, it can be executed actively at any time the device remains connected by sending a specific request HTTP packet that will trigger an HTTP response from the AP. In case a captive portal is not detected in AP, an HTTP request can be sent directly to the gateway IP of the AP to obtain a response from the AP gateway HTTP server.

權(quán)利要求

1
微信群二維碼
意見反饋