- 专利标题: Detecting DGA-based malicious software using network flow information
-
申请号: US14448637申请日: 2014-07-31
-
公开(公告)号: US09654484B2公开(公告)日: 2017-05-16
- 发明人: Martin Grill , Ivan Nikolaev
- 申请人: Cisco Technology, Inc.
- 申请人地址: US CA San Jose
- 专利权人: Cisco Technology, Inc.
- 当前专利权人: Cisco Technology, Inc.
- 当前专利权人地址: US CA San Jose
- 代理机构: Hickman Palermo Becker Bingham LLP
- 代理商 Malgorzata A. Kulczycka
- 主分类号: H04L29/00
- IPC分类号: H04L29/00 ; H04L29/06 ; H04L29/08 ; H04L29/12
摘要:
Detecting DGA-based malware is disclosed. In an embodiment, a number of domain name server requests originating from a particular host among a plurality of hosts is determined. The number of domain name server requests are directed to one or more domain name servers. A number of internet protocol addresses contacted by the particular host is determined. Based on the number of domain name server requests and the number of internet protocol addresses contacted existence of malware on the particular host is determined.
公开/授权文献
信息查询