APPARATUS AND METHOD FOR DETECTING MALICIOUS DOMAIN CLUSTER
    1.
    发明申请
    APPARATUS AND METHOD FOR DETECTING MALICIOUS DOMAIN CLUSTER 有权
    用于检测恶性域簇的装置和方法

    公开(公告)号:US20160294859A1

    公开(公告)日:2016-10-06

    申请号:US14735579

    申请日:2015-06-10

    Abstract: An apparatus and method for detecting a malicious domain cluster. The apparatus for detecting a malicious domain cluster includes a domain name server (DNS) data collection unit and a malicious domain cluster detection unit. The DNS data collection unit collects DNS traffic over a network, and stores the DNS traffic in a database. The malicious domain cluster detection unit generates a domain cluster based on the DNS data, learns the characteristics of normal and malicious clusters in the domain cluster, and detects whether the domain cluster is malicious based on the result of the learning.

    Abstract translation: 一种用于检测恶意域群集的装置和方法。 用于检测恶意域群集的装置包括域名服务器(DNS)数据收集单元和恶意域群集检测单元。 DNS数据收集单元通过网络收集DNS流量,并将DNS流量存储在数据库中。 恶意域群集检测单元根据DNS数据生成域集群,学习域群中正常和恶意群集的特征,根据学习结果,检测域群集是否恶意。

    SYSTEM AND METHOD FOR DETECTING MALWARE BASED ON VIRTUAL HOST
    2.
    发明申请
    SYSTEM AND METHOD FOR DETECTING MALWARE BASED ON VIRTUAL HOST 审中-公开
    基于虚拟主机检测恶意软件的系统和方法

    公开(公告)号:US20150089655A1

    公开(公告)日:2015-03-26

    申请号:US14492177

    申请日:2014-09-22

    CPC classification number: H04L63/145 G06F21/566 H04L63/1425

    Abstract: A system and method for detecting malware based on a virtual host are provided. The system for detecting malware based on a virtual host includes a terminal network behavior analysis server and a virtual host. The terminal network behavior analysis server extracts network behavior information by monitoring the network behavior of an actual host, and outputs the extracted the network behavior information. The virtual host detects malware corresponding to abnormal behavior in the actual host, by receiving the network behavior information and then performing corresponding behavior.

    Abstract translation: 提供了一种基于虚拟主机来检测恶意软件的系统和方法。 用于基于虚拟主机检测恶意软件的系统包括终端网络行为分析服务器和虚拟主机。 终端网络行为分析服务器通过监控实际主机的网络行为来提取网络行为信息,并输出提取的网络行为信息。 虚拟主机通过接收网络行为信息,然后执行相应的行为来检测与实际主机异常行为相对应的恶意软件。

Patent Agency Ranking