首页> 外国专利> DISTRIBUTED TRAFFIC PATTERN ANALYSIS AND ENTROPY PREDICTION FOR DETECTING MALWARE IN A NETWORK ENVIRONMENT

DISTRIBUTED TRAFFIC PATTERN ANALYSIS AND ENTROPY PREDICTION FOR DETECTING MALWARE IN A NETWORK ENVIRONMENT

机译:网络环境中恶意软件的分布式流量模式分析和熵预测

摘要

Technologies are provided in embodiments to detect malware. The embodiments are configured to receive an entropy rate of a potentially affected system. The embodiments are further configured to compare the entropy rate to an average entropy rate, and to determine a probability that the potentially affected system is infected with malware. The probability is based, at least in part, on a result of the comparison. More specific embodiments can include the received entropy rate being generated, at a least in part, by a genetic program. Additional embodiments can include a configuration to provide the potentially affected system with a specified time-span associated with the genetic program. The specified time-span indicates an amount of time to observe context information on the potentially affected system. In at least some embodiments, the result of the comparison includes an indicator of whether the entropy rate correlates to an infected system or a healthy system.
机译:在实施例中提供了检测恶意软件的技术。实施例被配置为接收潜在受影响系统的熵率。实施例还被配置为将熵率与平均熵率进行比较,并确定潜在受影响的系统被恶意软件感染的概率。概率至少部分地基于比较的结果。更具体的实施例可以包括至少部分地由遗传程序生成的接收到的熵率。另外的实施例可以包括一种配置,以向潜在受影响的系统提供与遗传程序相关联的指定时间跨度。指定的时间跨度表示观察潜在受影响系统上的上下文信息所需的时间。在至少一些实施例中,比较的结果包括指示熵率与感染系统或健康系统相关的指标。

著录项

  • 公开/公告号EP2979220B1

    专利类型

  • 公开/公告日2017-11-22

    原文格式PDF

  • 申请/专利权人 INTEL CORP;

    申请/专利号EP20140774368

  • 发明设计人 VAN DE VEN ADRIAAN;HOHNDEL DIRK;

    申请日2014-03-27

  • 分类号G06F21/56;H04L29/06;G06F21/55;G06N3/12;

  • 国家 EP

  • 入库时间 2022-08-21 13:17:27

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号