首页> 外国专利> Malicious network activity detection utilising a model of user contact lists built up from monitoring network communications

Malicious network activity detection utilising a model of user contact lists built up from monitoring network communications

机译:利用通过监视网络通信建立的用户联系人列表模型进行恶意网络活动检测

摘要

This invention relates to a method for detecting malicious communication activity between user devices 22, 24, 26, 28 in an electronic communications network. Source and destination data from electronic communications made across the network are used to derive contact data such as telephone numbers, email addresses and Internet Protocol (IP) addresses. These contact data are used to model 58 the contents of the actual contact lists 32, 34, 36, 38 stored on user devices, without the need to individually access each of the user devices themselves. Once the models have been created, source and destination data from further electronic communications are analysed for suspicious patterns of activity, with reference to the contact list models. Malware, which propagate by scanning infected user devices for contacts of other user devices to infect and sending copies of themselves on to infect other devices, can therefore be detected.
机译:本发明涉及一种用于检测电子通信网络中的用户设备22、24、26、28之间的恶意通信活动的方法。跨网络进行的电子通信中的源数据和目标数据用于导出联系人数据,例如电话号码,电子邮件地址和Internet协议(IP)地址。这些联系人数据用于对存储在用户设备上的实际联系人列表32、34、36、38的内容进行建模58,而不需要单独访问每个用户设备本身。一旦创建了模型,将参考联系人列表模型分析来自进一步电子通信的源和目标数据的可疑活动模式。因此,可以检测到恶意软件,该恶意软件通过扫描受感染的用户设备以寻找其他用户设备的联系人进行感染并传播其自身副本以感染其他设备而传播。

著录项

  • 公开/公告号GB2436190A

    专利类型

  • 公开/公告日2007-09-19

    原文格式PDF

  • 申请/专利权人 ORANGE SA;

    申请/专利号GB20060004605

  • 发明设计人 ISABELLE RAVOT;ERIC GAUTHIER;

    申请日2006-03-07

  • 分类号G06F21;

  • 国家 GB

  • 入库时间 2022-08-21 20:26:04

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号