首页> 外国专利> UTILIZING CLUSTERING TO IDENTIFY IP ADDRESSES USED BY A BOTNET

UTILIZING CLUSTERING TO IDENTIFY IP ADDRESSES USED BY A BOTNET

机译:利用群集来识别僵尸网络使用的IP地址

摘要

Methods and systems are provided for identifying suspect Internet Protocol (IP) addresses, in accordance with embodiments described herein. In particular, embodiments described herein include obtaining a set of login pairs comprising login identifiers (e.g., user identifiers) and IP addresses used in attempts to login to a source. A set of IP clusters is generated using the set of login pairs. Each IP cluster can include one or more IP addresses identified as related based on a login identifier being used to attempt to login to the source via multiple IP addresses or an IP address being used to attempt to login to the source via multiple login identifiers. Thereafter, it is determined that a particular IP cluster exceeds a threshold amount of IP addresses. Each of the IP addresses within the particular IP cluster is designated as a suspect IP address.
机译:根据本文描述的实施例,提供了用于识别可疑互联网协议(IP)地址的方法和系统。 特别地,本文描述的实施例包括获得包括登录标识符(例如,用户标识符)的一组登录对和用于登录到源的尝试中使用的IP地址。 使用该组登录对生成一组IP集群。 每个IP集群可以包括基于用于尝试通过多个IP地址或用于经由多个登录标识符登录源登录到源的登录标识符的一个或多个IP地址识别为相关的IP地址。 此后,确定特定IP簇超过IP地址的阈值量。 特定IP集群中的每个IP地址被指定为可疑IP地址。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号