• 专利标题: METHOD FOR DETECTION OF LATERAL MOVEMENT OF MALWARE
  • 申请号: US17842714
    申请日: 2022-06-16
  • 公开(公告)号: US20220407876A1
    公开(公告)日: 2022-12-22
  • 发明人: Ravi RAMANVinod VASUDEVANHarshvardhan PARMAR
  • 申请人: BULL SAS
  • 申请人地址: FR Les Clayes-sous-Bois
  • 专利权人: BULL SAS
  • 当前专利权人: BULL SAS
  • 当前专利权人地址: FR Les Clayes-sous-Bois
  • 优先权: EP21179791.5 20210616
  • 主分类号: H04L9/40
  • IPC分类号: H04L9/40
METHOD FOR DETECTION OF LATERAL MOVEMENT OF MALWARE
摘要:
A method for detecting malware penetrating a network by identifying anomalous communication between at least two systems of the network, carried out by a computer. For each unique combination of Source IP address and destination IP address, the method includes considering a past period, considering the network flow logs stored during said past period, calculating values of a metric based on data of the network flow logs within the past period and at a given frequency, calculating a baseline which consists in calculating an IQR of all metric values calculated during the past period, determining an outlier threshold from the baseline, considering a current period, calculating a new IQR of all metric values calculated during the current period, and classifying the communication between the two systems of the unique combination as an anomalous communication if the IQR of the current period is greater than the outlier threshold.
公开/授权文献
信息查询
0/0