首页> 外国专利> system and method of detecting malware with an algorithm generating domain names and systems contaminated with such malicious programs

system and method of detecting malware with an algorithm generating domain names and systems contaminated with such malicious programs

机译:用生成域名的算法和被此类恶意程序污染的系统来检测恶意软件的系统和方法

摘要

Systems and methods for detection of domain generated algorithms (DGA) and their command and control (C&C) servers are disclosed. In one embodiment, such an approach includes examining DNS queries for DNS resolution failures, and monitoring certain set of parameters such as number of levels, length of domain name, lexical complexity, and the like for each failed domain. These parameters may then be compared against certain thresholds to determine if the domain name is likely to be part of a DGA malware. Domain names identified as being part of a DGA malware may then be grouped together. Once a DGA domain name has been identified, activity from that domain name can be monitored to detect successful resolutions from the same source to see if any of the successful domain resolutions match these parameters. If they match specific thresholds, then the domain is determined to be a C&C server of the DGA malware and may be identified as such.
机译:公开了用于检测域生成算法(DGA)及其命令和控制(C&C)服务器的系统和方法。在一个实施例中,这样的方法包括检查DNS查询失败的DNS查询,以及监视每个失败域的某些参数集,例如级别数,域名长度,词法复杂性等。然后可以将这些参数与某些阈值进行比较,以确定域名是否可能是DGA恶意软件的一部分。然后,可以将识别为DGA恶意软件一部分的域名分组在一起。标识DGA域名后,可以监视该域名的活动以检测来自同一来源的成功解析,以查看是否有任何成功的域名解析与这些参数匹配。如果它们与特定阈值匹配,则该域被确定为DGA恶意软件的C&C服务器,并且可以这样标识。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号