首页> 外国专利> CYBER SECURITY ADAPTIVE ANALYTICS THREAT MONITORING SYSTEM AND METHOD

CYBER SECURITY ADAPTIVE ANALYTICS THREAT MONITORING SYSTEM AND METHOD

机译:网络安全自适应分析威胁监测系统及方法

摘要

A system and method of detecting command and control behavior of malware on a client computer is disclosed. One or more DNS messages are monitored from one or more client computers to a DNS server to determine a risk that one or more client computers is communicating with a botnet. Real-time entity profiles are generated for at least one of each of the one or more client computers, DNS domain query names, resolved IP addresses of query domain names, client computer-query domain name pairs, pairs of query domain name and corresponding resolved IP address, or query domain name-IP address cliques based on each of the one or more DNS messages. Using the real-time entity profiles, a risk that any of the one or more client computers is infected by malware that utilizes DNS messages for command and control or illegitimate data transmission purposes is determined. One or more scores are generated representing probabilities that one or more client computers is infected by malware.
机译:公开了一种检测客户端计算机上的恶意软件的命令和控制行为的系统和方法。将从一台或多台客户端计算机到DNS服务器的一个或多个DNS消息进行监视,以确定一台或多台客户端计算机与僵尸网络进行通信的风险。为一个或多个客户端计算机,DNS域查询名称,查询域名的解析IP地址,客户端计算机-查询域名对,查询域名对和相应的解析域名中的至少一个生成实时实体配置文件基于一个或多个DNS消息中的每一个的IP地址或查询域名-IP地址组。使用实时实体配置文件,可以确定一个或多个客户端计算机中的任何一个受到恶意软件感染的风险,该恶意软件利用DNS消息进行命令和控制或非法数据传输。生成一个或多个分数,表示一个或多个客户端计算机被恶意软件感染的可能性。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号