首页> 外国专利> Command source identifying apparatus, command source identification method, and the command source identification program

Command source identifying apparatus, command source identification method, and the command source identification program

机译:指令源识别装置,指令源识别方法和指令源识别程序

摘要

PROBLEM TO BE SOLVED: To identify a commander device for giving an operation command to an infected device via a C & C server and to enable disconnection between the commander device and the C & C server.SOLUTION: A command source identification device comprises: acquisition means for acquiring information on a packet involved in the communication between an opposite device for communicating with a predetermined server and the predetermined server; grouping means for grouping the opposite device according to whether the communication meets a predetermined condition or not on the basis of the information on the packet acquired by the acquisition means; and identification means for identifying an opposite device belonging to a group with the number of devices belonging thereto is smaller than other groups among the groups obtained by grouping by the grouping means as a commander device candidate for giving a command to opposite devices other than the opposite device via the predetermined server.
机译:解决的问题:识别用于通过C&C服务器向受感染设备发出操作命令的指挥官设备,并使指挥官设备与C&C服务器之间的连接断开。解决方案:命令源识别设备包括:采集用于获取与用于与预定服务器进行通信的相对设备之间的通信中涉及的分组的信息的装置;分组装置,用于基于由获取装置获取的关于分组的信息,根据通信是否满足预定条件来对对方设备进行分组;用于识别属于一个组的对端设备的识别装置,该装置的数量要小于通过分组装置进行分组而获得的组中的其他组,作为用于向对端以外的对端设备发出命令的命令方候选设备设备通过预定的服务器。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号