发明授权
- 专利标题: System and method for detection of targeted attacks
- 专利标题(中): 用于检测目标攻击的系统和方法
-
申请号: US14484891申请日: 2014-09-12
-
公开(公告)号: US09386031B2公开(公告)日: 2016-07-05
- 发明人: Victor V. Yablokov
- 申请人: Kaspersky Lab ZAO
- 申请人地址: RU Moscow
- 专利权人: AO Kaspersky Lab
- 当前专利权人: AO Kaspersky Lab
- 当前专利权人地址: RU Moscow
- 代理机构: Arent Fox LLP
- 代理商 Michael Fainberg
- 主分类号: G06F11/00
- IPC分类号: G06F11/00 ; H04L29/06
摘要:
Methods, systems, and computer programs for detecting targeted attacks on compromised computer. An example method includes receiving from a plurality of computer systems data about the network resource, wherein each of the plurality of computer systems has a set of parameters and associated parameter values; detecting presence of a suspect indicator in the respective data received from each of a first group of the plurality of computer systems; detecting absence of the suspect indicator in the respective data received from each of a second group of the plurality of computer systems; determining at least one suspect parameter and at least one suspect parameter value; and estimating a probability of the targeted attack from the network resource based on the suspect indicator, the at least one suspect parameter, and the at least one parameter value.
公开/授权文献
- US20160080398A1 SYSTEM AND METHOD FOR DETECTION OF TARGETED ATTACKS 公开/授权日:2016-03-17
信息查询