首页> 外国专利> SYSTEM AND METHODS FOR DETECTING DOMAIN GENERATION ALGORITHM (DGA) MALWARE

SYSTEM AND METHODS FOR DETECTING DOMAIN GENERATION ALGORITHM (DGA) MALWARE

机译:检测域生成算法(DGA)恶意软件的系统和方法

摘要

Domain generation algorithm (DGA) malware is detected by intercepting an external time request sent by a potential DGA malware host, and replacing the received real time with an accelerated (future) real time designed to trigger time-dependent DGA activity. The interception and replacement are performed outside the physical or virtual DGA host, on a different physical or virtual system such as a distinct external physical server or router, or distinct hypervisor or virtual machine running on the same physical system, in order to reduce the risk that the DGA malware identifies the time substitution. Failed DGA malware external access requests triggered only at future times are then used to identify domain names generated by the DGA malware, allowing proactive countermeasures.
机译:通过拦截由潜在的DGA恶意软件主机发送的外部时间请求来检测域生成算法(DGA)恶意软件,并用旨在触发时间相关的DGA活动的加速(未来)实时更换所接收的实时。拦截和替换在物理或虚拟DGA主机之外,在不同的物理或虚拟系统(例如不同的外部物理服务器或路由器)外,或在同一物理系统上运行的不同的管理程序或虚拟机,以降低风险DGA恶意软件识别时间替换。然后,仅在将来时触发的DGA恶意软件外部访问请求失败用于识别DGA恶意软件生成的域名,允许主动对策。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号