发明授权
- 专利标题: Signature creation for malicious network traffic
- 专利标题(中): 恶意网络流量的签名创建
-
申请号: US12709432申请日: 2010-02-19
-
公开(公告)号: US08782790B1公开(公告)日: 2014-07-15
- 发明人: Spencer Smith , Adam Glick , Nicholas Graf , Uriel Mann
- 申请人: Spencer Smith , Adam Glick , Nicholas Graf , Uriel Mann
- 申请人地址: US CA Mountain View
- 专利权人: Symantec Corporation
- 当前专利权人: Symantec Corporation
- 当前专利权人地址: US CA Mountain View
- 代理机构: Fenwick & West LLP
- 主分类号: H04L29/06
- IPC分类号: H04L29/06
摘要:
An endpoint on a network uses detection data to detect a malicious software attack. The endpoint identifies content associated with the attack, such as a component of a web page, and generates a description of the content. The endpoint sends the description to a security server. The security server analyzes the content and identifies characteristics of the content that are present when the content is carried by network traffic. The security server generates a traffic signature that specifies the identified characteristics and provides the traffic signature to inspection points. The inspection points, in turn, use the traffic signature to examine network traffic passing through the inspection points to detect network traffic carrying the content. The attack detection at the endpoint thus informs the traffic signature-based detection at the inspection points and reduces the spread of malicious software.
信息查询