- 专利标题: Non-protocol specific system and method for classifying suspect IP addresses as sources of non-targeted attacks on cloud based machines
-
申请号: US15587588申请日: 2017-05-05
-
公开(公告)号: US10511615B2公开(公告)日: 2019-12-17
- 发明人: Royi Ronen , Hani Hana Neuvirth , Tomer Koren , Omer Karin
- 申请人: Microsoft Technology Licensing, LLC
- 申请人地址: US WA Redmond
- 专利权人: Microsoft Technology Licensing, LLC
- 当前专利权人: Microsoft Technology Licensing, LLC
- 当前专利权人地址: US WA Redmond
- 代理机构: Workman Nydegger
- 主分类号: H04L29/06
- IPC分类号: H04L29/06 ; H04L12/26 ; G06N20/00 ; H04L29/08
摘要:
A system for detecting a non-targeted attack by a first machine on a second machine is provided. The system includes an application that includes instructions configured to: extract network data corresponding to traffic flow between the first and second machines, where the second machine is implemented in a cloud-based network; identify a first suspect external IP address based on the network data; calculate features for the first suspect external IP address, where the features include exploration type features and exploitation type features; train a classifier based on predetermined examples and the features to generate and update a model; classify the first suspect external IP address based on the model and at least some of the features; and perform a countermeasure if a classification provided from classifying the first suspect external IP address indicates that the first suspect external IP address is associated with a malicious attack on the second machine.
公开/授权文献
信息查询