发明授权
- 专利标题: Detecting malicious behaviour on a computer network
- 专利标题(中): 检测计算机网络上的恶意行为
-
申请号: US13202424申请日: 2010-02-23
-
公开(公告)号: US08966631B2公开(公告)日: 2015-02-24
- 发明人: Fadi El-Moussa
- 申请人: Fadi El-Moussa
- 申请人地址: GB London
- 专利权人: British Telecommunications PLC
- 当前专利权人: British Telecommunications PLC
- 当前专利权人地址: GB London
- 代理机构: Nixon & Vanderhye PC
- 优先权: EP09250487 20090224
- 国际申请: PCT/GB2010/000322 WO 20100223
- 国际公布: WO2010/097575 WO 20100902
- 主分类号: G06F21/00
- IPC分类号: G06F21/00 ; H04L29/06
摘要:
A malicious behavior detector (100) for detecting malicious behavior on a network, comprises a processor unit (120) and associated system memory (130) containing computer program code. The computer program code provides a signature matching module (132) to perform malicious partial signature detection by reading the contents of packets of data passing through the network to look for partial signatures associated with malicious programs; a Domain Name Service, DNS, request and/or response detection module (134) to monitor the requests made by hosts connected to the network and/or responses thereto; and an evidence assessment module (138) to analyze the results of the partial signature detection and the DNS monitoring make a determination of the suspected presence of malicious behavior on the network based upon the analysis of the results of both the partial signature detection and the DNS monitoring.
公开/授权文献
- US20110302656A1 DETECTING MALICIOUS BEHAVIOUR ON A COMPUTER NETWORK 公开/授权日:2011-12-08
信息查询