首页> 外国专利> Discovery of IP addresses of nodes in a botnet

Discovery of IP addresses of nodes in a botnet

机译:发现僵尸网络中节点的IP地址

摘要

A method of discovering suspect Internet Protocol (IP) addresses comprises, at each of a multiplicity of clients, monitoring for malware and, on detection of malware, obtaining a list of IP addresses with which a connection has been made or attempted at the client computer within a preceding time frame. Each client sends the list of IP addresses to a central server and receives in return a blacklist of suspect IP addresses to allow the client computers to block connections with IP addresses within the blacklist. The client may filter out IP addresses to which trivial connections were made prior to sending the list. The sever removes safe IP addresses and adds the remaining addresses to a database. The suspect IP addresses may relate to nodes within a botnet. The invention works in conjunction with existing antivirus software and the crowd sourcing method is made possible because antivirus software providers typically have a large subscriber base.
机译:一种发现可疑Internet协议(IP)地址的方法,该方法包括在多个客户端中的每个客户端上监视恶意软件,并在检测到恶意软件时,获取已在客户端计算机上建立或尝试与其建立连接的IP地址列表。在之前的时间范围内。每个客户端将IP地址列表发送到中央服务器,并作为回报接收可疑IP地址黑名单,以允许客户端计算机阻止与该黑名单中IP地址的连接。客户端可以在发送列表之前过滤掉进行了简单连接的IP地址。服务器将删除安全IP地址,并将其余地址添加到数据库中。可疑IP地址可能与僵尸网络内的节点有关。本发明与现有的防病毒软件结合工作,并且众包方法成为可能,因为防病毒软件提供商通常具有大量的用户基础。

著录项

  • 公开/公告号GB2502254A

    专利类型

  • 公开/公告日2013-11-27

    原文格式PDF

  • 申请/专利权人 F-SECURE CORPORATION;

    申请/专利号GB20120006935

  • 发明设计人 PAVEL TURBIN;

    申请日2012-04-20

  • 分类号H04L29/06;

  • 国家 GB

  • 入库时间 2022-08-21 15:35:54

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号