会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 10. 发明申请
    • SYSTEM AND METHOD FOR DETECTION OF DOMAIN-FLUX BOTNETS AND THE LIKE
    • 用于检测域网通网络的系统和方法
    • US20120084860A1
    • 2012-04-05
    • US12897494
    • 2010-10-04
    • Jin CaoLi LiNan Jiang
    • Jin CaoLi LiNan Jiang
    • G06F11/00
    • H04L63/1441H04L2463/144
    • In one embodiment, a method for detecting malicious software agents, such as domain-flux botnets. The method applies a co-clustering algorithm on a domain-name query failure graph, to generate a hierarchical grouping of hosts based on similarities between domain names queried by those hosts, and divides that hierarchical structure into candidate clusters based on percentages of failed queries having at least first- and second-level domain names in common, thereby identifying hosts having correlated queries as possibly being infected with malicious software agents. A linking algorithm is used to correlate the co-clustering results generated at different time periods to differentiate actual domain-flux bots from other domain-name failure anomalies by identifying candidate clusters that persist for relatively long periods of time. Persistent candidate clusters are analyzed to identify which clusters have malicious software agents, based on a freshness metric that characterizes whether the candidate clusters continually generate failed queries having new domain names.
    • 在一个实施例中,一种用于检测恶意软件代理的方法,例如域通量僵尸网络。 该方法在域名查询失败图上应用共同聚合算法,根据这些主机查询的域名之间的相似性生成主机的分层分组,并根据失败查询的百分比将该层次结构划分为候选集群 至少一级和二级域名,从而识别具有可能被恶意软件代理感染的相关查询的主机。 使用链接算法将在不同时间段产生的共聚集结果相关联,以通过识别持续相对较长时间段的候选聚类来区分实际的域通量bot与其他域名失败异常。 分析持续的候选聚类,以基于表征候选集群是否持续生成具有新域名的失败查询的新鲜度量来识别哪些集群具有恶意软件代理。