首页> 外国专利> SYSTEM AND METHOD FOR DETECTING A MALICIOUS COMMAND AND CONTROL CHANNEL

SYSTEM AND METHOD FOR DETECTING A MALICIOUS COMMAND AND CONTROL CHANNEL

机译:检测恶意命令和控制通道的系统和方法

摘要

A method is provided in one example embodiment that includes detecting repetitive connections from a source node to a destination node, calculating a score for the source node based on the connections, and taking a policy action if the score exceeds a threshold score. In more particular embodiments, the repetitive connections use a hypertext transfer protocol and may include connections to a small number of unique domains, connections to small number of unique resources associated with the destination node, and/or a large number of connections to a resource in a domain. Moreover, heuristics may be used to score the source node and identify behavior indicative of a threat, such as a bot or other malware.
机译:在一个示例实施例中提供了一种方法,该方法包括:检测从源节点到目的地节点的重复连接;基于该连接计算源节点的分数;以及如果该分数超过阈值分数,则采取策略动作。在更特定的实施例中,重复连接使用超文本传输​​协议,并且可以包括到少量唯一域的连接,到少量与目的地节点相关联的唯一资源的连接和/或到资源中的大量连接。域。此外,试探法可用于对源节点进行评分并识别表示威胁的行为,例如机器人或其他恶意软件。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号