首页> 外国专利> Server-side malware detection and classification

Server-side malware detection and classification

机译:服务器端恶意软件检测和分类

摘要

A server-side system that detects and classifies malware and other types of undesirable processes and events operating on network connected devices through the analysis of information collected from said network connected devices. The system receives information over a network connection and collects information that is identified as being anomalous. The collected information is analyzed by system process that can group data based on optimally suited cluster analysis methods. Upon clustering the information, the system can correlate an anomalous event to device status, interaction, and various elements that constitute environmental data in order to identify a pattern of behavior associated with a known or unknown strain of malware. The system further interprets the clustered information to extrapolate propagation characteristics of the strain of malware and determine a potential response action.
机译:一种服务器端系统,其通过对从所述网络连接的设备收集的信息进行分析,来检测和分类在网络连接的设备上运行的恶意软件和其他类型的不良进程和事件。该系统通过网络连接接收信息,并收集被标识为异常的信息。系统可以对收集到的信息进行分析,该系统可以根据最适合的聚类分析方法对数据进行分组。在对信息进行聚类后,系统可以将异常事件与设备状态,交互以及构成环境数据的各种元素相关联,以识别与已知或未知恶意软件菌株相关的行为模式。该系统进一步解释聚类的信息以推断恶意软件的传播特性并确定潜在的响应动作。

著录项

  • 公开/公告号US9411955B2

    专利类型

  • 公开/公告日2016-08-09

    原文格式PDF

  • 申请/专利权人 FATSKUNK INC.;

    申请/专利号US201313964001

  • 发明设计人 BJORN MARKUS JAKOBSSON;

    申请日2013-08-09

  • 分类号H04L29/06;G06F21/55;G06F21/56;

  • 国家 US

  • 入库时间 2022-08-21 14:28:44

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号