发明授权
- 专利标题: Identification of beaconing from network communication events of network traffic log
-
申请号: US17332289申请日: 2021-05-27
-
公开(公告)号: US11463331B1公开(公告)日: 2022-10-04
- 发明人: Martin Arlitt , Mijung Kim , Manish Marwah
- 申请人: MICRO FOCUS LLC
- 申请人地址: US CA Santa Clara
- 专利权人: MICRO FOCUS LLC
- 当前专利权人: MICRO FOCUS LLC
- 当前专利权人地址: US CA Santa Clara
- 主分类号: G06F15/173
- IPC分类号: G06F15/173 ; H04L43/028 ; H04L43/0817 ; H04L43/067 ; H04L43/106
摘要:
Network communication events are filtered to remove the network communication events having a predicted unrelatedness to beaconing. Each network communication event has a timestamp, a source entity, and a destination entity. The filtered network communication events are aggregated by unique source entity-destination entity pairs. For each unique source entity-destination entity pair, the network communication events are timestamp-sorted, time differentials between the timestamps of adjacent network communication events are calculated, and a beacon likelihood metric is calculated from the calculated time differentials. Which of the unique source entity-destination entity pairs are indicative of beaconing are identified based on the beacon likelihood metric calculated for each unique source entity-destination entity pair.
信息查询