发明授权
- 专利标题: Method, apparatus, and system for detecting a zombie host
- 专利标题(中): 用于检测僵尸主机的方法,装置和系统
-
申请号: US13238680申请日: 2011-09-21
-
公开(公告)号: US08627477B2公开(公告)日: 2014-01-07
- 发明人: Xu Chen , Shuo Shen
- 申请人: Xu Chen , Shuo Shen
- 申请人地址: CN Shenzhen
- 专利权人: Huawei Technologies Co., Ltd.
- 当前专利权人: Huawei Technologies Co., Ltd.
- 当前专利权人地址: CN Shenzhen
- 代理机构: Leydig, Voit & Mayer, Ltd.
- 优先权: CN200910106341 20090323
- 主分类号: H04L29/06
- IPC分类号: H04L29/06
摘要:
The present invention relates to the communications field, and in particular, to a detection method, an apparatus, and a network with detection functions. The present invention solves the problem that the Botnet cannot be detected on a current communication network. The detection method is used to detect a Botnet and includes: obtaining a network address translation (NAT) table; detecting a behavior plane and a communication plane of a host according to the NAT table; and performing cluster analysis on results of detection on the communication plane and the behavior plane.
公开/授权文献
信息查询