发明授权
US09386028B2 System and method for malware detection using multidimensional feature clustering
有权
使用多维特征聚类进行恶意软件检测的系统和方法
- 专利标题: System and method for malware detection using multidimensional feature clustering
- 专利标题(中): 使用多维特征聚类进行恶意软件检测的系统和方法
-
申请号: US14060933申请日: 2013-10-23
-
公开(公告)号: US09386028B2公开(公告)日: 2016-07-05
- 发明人: Yuval Altman
- 申请人: Verint Systems Ltd.
- 申请人地址: IL Herzilya Pituach
- 专利权人: VERINT SYSTEMS LTD.
- 当前专利权人: VERINT SYSTEMS LTD.
- 当前专利权人地址: IL Herzilya Pituach
- 代理机构: Meunier Carlin & Curfman
- 优先权: IL222648 20121023
- 主分类号: G06F11/00
- IPC分类号: G06F11/00 ; G06F12/14 ; G06F12/16 ; G08B23/00 ; H04L29/06 ; G06F21/56 ; G06F21/55
摘要:
Methods and systems for malware detection techniques, which detect malware by identifying the Command and Control (C&C) communication between the malware and the remote host, and distinguish between communication transactions that carry C&C communication and transactions of innocent traffic. The fine-granularity features are examined, which are present in the transactions and are indicative of whether the transactions are exchanged with malware. A feature comprises an aggregated statistical property of one or more features of the transactions, such as average, sum median or variance, or of any suitable function or transformation of the features.
公开/授权文献
信息查询