发明授权
- 专利标题: Determination of participation in a malicious software campaign
- 专利标题(中): 决定参与恶意软件运动
-
申请号: US11767860申请日: 2007-06-25
-
公开(公告)号: US07899870B2公开(公告)日: 2011-03-01
- 发明人: Malcolm Erik Pearson , Mihai Costea
- 申请人: Malcolm Erik Pearson , Mihai Costea
- 申请人地址: US WA Redmond
- 专利权人: Microsoft Corporation
- 当前专利权人: Microsoft Corporation
- 当前专利权人地址: US WA Redmond
- 代理机构: Woodcock Washburn LLP
- 主分类号: G06F15/16
- IPC分类号: G06F15/16
摘要:
Sources of spam, such as botnets, are detected by analyzing message traffic for behavioral patterns and indications of suspicious content. The content of a known malicious source is analyzed. Message traffic associated with the known malicious source is analyzed. Associated message traffic includes messages sent directly from the known malicious source to recipients, and messages sent from the recipients to subsequent direct and indirect recipients. Portions of the content of the known malicious source are selected and content of associated message traffic is analyzed for an indication of the selected content. If the selected content is found in the content of a message, the source of the message is determined to be a source of spam. Associated message traffic is additionally analyzed for behavioral patterns, such as anomalies and/or flurries of activity, to determine a potential malicious source.
公开/授权文献
信息查询