首页> 外国专利> System and method for tracking malware route and behavior for defending against cyberattacks

System and method for tracking malware route and behavior for defending against cyberattacks

机译:跟踪恶意软件路由和行为以防御网络攻击的系统和方法

摘要

An attack tracking system includes multiple hosts in which first event data concerning object behavior are collected and pieces of host-based event information are created therefrom; a tracking information database server storing the pieces of host-based event information; a tracking information analysis server creating behavior events by defining malware behavior from the pieces of host-based event information, retrieving targets to be analyzed from the pieces of host-based event information and the behavior events based on a preset input value, creating first tracking contexts for identifying the malware behavior by analyzing the relationship between the pieces of host-based event information and the relationship between a set of the pieces of host-based event information and a set of the behavior events, and creating second tracking contexts tracking malware routes and behavior events between the multiple hosts by analyzing the correlation between the first tracking contexts.
机译:一种攻击跟踪系统,包括多个主机,其中收集有关对象行为的第一事件数据,并从中创建基于主机的事件信息。跟踪信息数据库服务器,存储基于主机的事件信息;跟踪信息分析服务器通过从基于主机的事件信息中定义恶意软件行为,基于预设的输入值从基于主机的事件信息和行为事件中检索要分析的目标,来创建行为事件,并创建第一跟踪通过分析基于主机的事件信息之间的关系以及基于主机的事件信息的集合与行为事件的集合之间的关系来识别恶意软件行为的上下文,并创建跟踪恶意软件路由的第二跟踪上下文通过分析第一跟踪上下文之间的相关性,确定多个主机之间的行为事件。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号