首页> 外国专利> Detection of suspicious domains through graph inference algorithm processing of host-domain contacts

Detection of suspicious domains through graph inference algorithm processing of host-domain contacts

机译:通过主机域联系人的图形推理算法处理来检测可疑域

摘要

A processing device comprises a processor coupled to a memory and is configured to obtain data relating to communications initiated by host devices of a computer network of an enterprise, and to process the data to identify external domains contacted by the host devices. A graph inference algorithm is applied to analyze contacts of the host devices with the external domains in order to characterize one or more of the external domains as suspicious domains. The host devices are configured to counteract malware infection from the suspicious domains. The graph inference algorithm in some embodiments comprises a belief propagation algorithm, which may be initiated with one or more seeds corresponding to respective known suspicious domains or to respective ones of the external domains determined to be associated with command and control behavior. The processing device may be implemented in the computer network or an associated network security system.
机译:处理设备包括耦合到存储器的处理器,并且被配置为获取与由企业的计算机网络的主机设备发起的通信有关的数据,并处理该数据以识别由主机设备联系的外部域。图推论算法被应用于分析主机设备与外部域的联系,以便将一个或多个外部域表征为可疑域。主机设备配置为抵御来自可疑域的恶意软件感染。在一些实施例中,图推断算法包括置信传播算法,其可以由对应于各个已知可疑域或确定为与命令和控制行为相关联的各个外部域中的一个或多个种子来发起。该处理设备可以在计算机网络或相关联的网络安全系统中实现。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号