Invention Grant
US09380066B2 Distributed traffic pattern analysis and entropy prediction for detecting malware in a network environment
有权
分布式流量模式分析和熵预测,用于在网络环境中检测恶意软件
- Patent Title: Distributed traffic pattern analysis and entropy prediction for detecting malware in a network environment
- Patent Title (中): 分布式流量模式分析和熵预测,用于在网络环境中检测恶意软件
-
Application No.: US13853601Application Date: 2013-03-29
-
Publication No.: US09380066B2Publication Date: 2016-06-28
- Inventor: Dirk Hohndel , Adriaan van de Ven
- Applicant: Intel Corporation
- Applicant Address: US CA Santa Clara
- Assignee: Intel Corporation
- Current Assignee: Intel Corporation
- Current Assignee Address: US CA Santa Clara
- Agency: Patent Capital Group
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06N3/12 ; G06F21/55 ; G06F21/56

Abstract:
Technologies are provided in embodiments to detect malware. The embodiments are configured to receive an entropy rate of a potentially affected system. The embodiments are further configured to compare the entropy rate to an average entropy rate, and to determine a probability that the potentially affected system is infected with malware. The probability is based, at least in part, on a result of the comparison. More specific embodiments can include the received entropy rate being generated, at a least in part, by a genetic program. Additional embodiments can include a configuration to provide the potentially affected system with a specified time-span associated with the genetic program. The specified time-span indicates an amount of time to observe context information on the potentially affected system. In at least some embodiments, the result of the comparison includes an indicator of whether the entropy rate correlates to an infected system or a healthy system.
Public/Granted literature
Information query