首页>
外国专利>
Detection of suspicious domains through graph inference algorithm processing of host-domain contacts
Detection of suspicious domains through graph inference algorithm processing of host-domain contacts
展开▼
机译:通过主机域联系人的图形推理算法处理来检测可疑域
展开▼
页面导航
摘要
著录项
相似文献
摘要
A processing device comprises a processor coupled to a memory and is configured to obtain data relating to communications initiated by host devices of a computer network of an enterprise, and to process the data to identify external domains contacted by the host devices. A graph inference algorithm is applied to analyze contacts of the host devices with the external domains in order to characterize one or more of the external domains as suspicious domains. The host devices are configured to counteract malware infection from the suspicious domains. The graph inference algorithm in some embodiments comprises a belief propagation algorithm, which may be initiated with one or more seeds corresponding to respective known suspicious domains or to respective ones of the external domains determined to be associated with command and control behavior. The processing device may be implemented in the computer network or an associated network security system.
展开▼