首页> 外国专利> Systematic mining of associated server herds for uncovering malware and attack campaigns

Systematic mining of associated server herds for uncovering malware and attack campaigns

机译:系统地挖掘相关服务器群以发现恶意软件和攻击活动

摘要

A method for detecting malicious servers. The method includes analyzing network traffic data to generate a main similarity measure and a secondary similarity measure for each server pair found in the network traffic data, extracting a main subset and a secondary subset of servers based on the main similarity measure and the secondary similarity measure, identifying a server that belongs to the main subset and the secondary subset, and determining a suspicious score of the server based on at least a first similarity density measure of the main subset, a second similarity density measure of the secondary subset, and a commonality measure of the main subset and the secondary subset.
机译:一种检测恶意服务器的方法。该方法包括分析网络流量数据以为在网络流量数据中找到的每个服务器对生成主要相似性度量和次要相似性度量,基于主要相似性度量和次要相似性度量提取服务器的主要子集和次要子集,识别属于主要子集和次要子集的服务器,并至少基于主要子集的第一相似性密度度量,次要子集的第二相似性密度度量和共性来确定服务器的可疑分数主要子集和次要子集的度量。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号