发明授权
- 专利标题: Method and apparatus for detecting malicious software using handshake information
-
申请号: US14534429申请日: 2014-11-06
-
公开(公告)号: US09854000B2公开(公告)日: 2017-12-26
- 发明人: Daniel G. Wing , Flemming S. Andreasen , Kent K. Leung
- 申请人: Daniel G. Wing , Flemming S. Andreasen , Kent K. Leung
- 申请人地址: US CA San Jose
- 专利权人: Cisco Technology, Inc.
- 当前专利权人: Cisco Technology, Inc.
- 当前专利权人地址: US CA San Jose
- 代理商 P. Su
- 主分类号: G06F11/00
- IPC分类号: G06F11/00 ; H04L29/06
摘要:
In one embodiment, a method includes identifying unusual behavior with respect to a handshake between a first endpoint and a second endpoint that are included in a network, and determining whether the unusual behavior with respect to the handshake indicates presence of malicious software. The method also includes identifying at least one of the first endpoint and the second endpoint as potentially being infected by the malicious software if it is determined that the unusual behavior with respect to the handshake indicates the presence of malicious software.
公开/授权文献
信息查询