首页> 外国专利> SYSTEM FOR COLLECTING/ANALYSING BOT AND A METHOD THEREFOR, CAPABLE OF ANALYZING AND MANAGING WHETHER ANALYZED LOGS ARE BOTTED

SYSTEM FOR COLLECTING/ANALYSING BOT AND A METHOD THEREFOR, CAPABLE OF ANALYZING AND MANAGING WHETHER ANALYZED LOGS ARE BOTTED

机译:装瓶/分析BOT的系统及其方法,能够对已分析的日志进行分析和管理

摘要

PURPOSE: A system for collecting/analyzing bot and a method therefor are provided to collect added files and malicious codes included in a spam mail and a URL(Uniform Resource Locator) for accessing a website, thereby analyzing the added files and malicious codes under an operation system of a virtual environment.;CONSTITUTION: An operating system generates a log by accessing a botnet C&C(Command&Control) server according as a URL visiting log and an execution log are generated. A bot analysis/management module(300) derives that the URL visiting log and the execution log are botnet logs. The bot analysis/management module classifies pattern of the derived botnet logs. The bot analysis/management module stores and manages the classified botnet logs by each pattern.;COPYRIGHT KIPO 2010
机译:目的:提供一种用于收集/分析僵尸程序的系统及其方法,以收集垃圾邮件中包含的添加文件和恶意代码以及用于访问网站的URL(统一资源定位符),从而在组成:操作系统根据URL访问日志和执行日志,通过访问僵尸网络C&C(命令与控制)服务器来生成日志。僵尸网络分析/管理模块(300)得出URL访问日志和执行日志是僵尸网络日志。僵尸程序分析/管理模块对派生的僵尸网络日志的模式进行分类。僵尸程序分析/管理模块按每种模式存储和管理分类的僵尸网络日志。; COPYRIGHT KIPO 2010

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号