首页> 外国专利> METHOD OF AND SYSTEM FOR ANALYSIS OF INTERACTION PATTERNS OF MALWARE WITH CONTROL CENTERS FOR DETECTION OF CYBER ATTACK

METHOD OF AND SYSTEM FOR ANALYSIS OF INTERACTION PATTERNS OF MALWARE WITH CONTROL CENTERS FOR DETECTION OF CYBER ATTACK

机译:用于检测网络攻击的带有控制中心的恶意软件交互模式的分析方法和系统

摘要

This technical solution relates to systems and methods of cyber attack detection, and more specifically it relates to analysis methods and systems for protocols of interaction of malware and cyber attack detection and control centers (servers). The analysis method for a protocol of interaction of malware and cyber attack detection and control centers involves planting of at least one piece of malware into at least one virtual environment, collection of requests sent by at least one of the said pieces of malware to at least one malware control center, determination of parameters and their sequence in the requests collected, grouping of requests with identical sets of parameters, generation of a regular expression describing parameters for each group of requests containing two or more requests, generation and sending of at least one request described by the regular expression obtained at the previous step to at least one malware control center, reception of at least one response from at least one malware control center and its decoding and/or decryption if this response is encoded and/or encrypted, analysis of at least one of the said responses for presence of information and data characteristic of cyber attacks, and saving of the results obtained. The technical result lies in improvement of efficiency of cyber attack detection.
机译:该技术方案涉及网络攻击检测的系统和方法,更具体地说,涉及用于恶意软件与网络攻击检测和控制中心(服务器)的交互协议的分析方法和系统。用于恶意软件和网络攻击检测与控制中心的交互协议的分析方法包括将至少一种恶意软件植入至少一个虚拟环境中,收集至少一个所述恶意软件向至少一个发送的请求。一个恶意软件控制中心,确定收集到的请求中的参数及其顺序,使用相同的参数集对请求进行分组,生成描述包含两个或多个请求的每组请求的参数的正则表达式,生成并发送至少一个由上一步获得的正则表达式描述的请求发送给至少一个恶意软件控制中心,从至少一个恶意软件控制中心接收至少一个响应,以及如果对该响应进行了编码和/或加密,则对其进行解码和/或解密分析至少一项上述回应,指出存在网络攻击所特有的信息和数据,并保存了获得的结果。技术成果在于提高网络攻击检测的效率。

著录项

  • 公开/公告号EP3267350B1

    专利类型

  • 公开/公告日2019-08-21

    原文格式PDF

  • 申请/专利权人 TRUST LTD.;

    申请/专利号EP20170180099

  • 发明设计人 VOLKOV DMITRY ALEKSANDROVICH;

    申请日2017-07-06

  • 分类号G06F21/56;H04L29/06;

  • 国家 EP

  • 入库时间 2022-08-21 12:30:25

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号