会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 4. 发明授权
    • Command and control channel detection with query string signature
    • 命令和控制通道检测与查询字符串签名
    • US08561188B1
    • 2013-10-15
    • US13250928
    • 2011-09-30
    • Jui Pang WangMing-Tai ChangJui-Chieh Wu
    • Jui Pang WangMing-Tai ChangJui-Chieh Wu
    • G06F21/00
    • H04L63/1425
    • Detection and prevention of botnet behavior is accomplished by monitoring access request in a network. Each request includes a domain of content to access and a path of content to access, and each path includes a file name and query string. Once obtained, the query strings for each of these requests are normalized. A signature is then created for each of the normalized query strings. The obtained requests can then be grouped by signature. Once the requests have been grouped by signature, each grouping is examined to identify suspicious signatures based on common botnet behavior. Suspicious requests are used in back-end and front-end defenses against botnets.
    • 通过监控网络中的访问请求来实现僵尸网络行为的检测和预防。 每个请求都包括要访问的内容的域和要访问的内容的路径,并且每个路径都包含文件名和查询字符串。 一旦获得,这些请求中的每一个的查询字符串被归一化。 然后为每个规范化查询字符串创建一个签名。 所获得的请求可以通过签名分组。 一旦通过签名对请求进行了分组,则根据常见的僵尸网络行为检查每个分组以识别可疑签名。 可疑请求用于后端和前端针对僵尸网络的防御。