- 专利标题: Method, device and system for recognizing network behavior of program
-
申请号: US14653335申请日: 2013-09-17
-
公开(公告)号: US09749341B2公开(公告)日: 2017-08-29
- 发明人: Haisu Liu , Cong Zhang , Yuzhi Xiong
- 申请人: BEIJING QIHOO TECHNOLOGY COMPANY LIMITED
- 申请人地址: CN Beijing
- 专利权人: Beijing Qihoo Technology Company Limited
- 当前专利权人: Beijing Qihoo Technology Company Limited
- 当前专利权人地址: CN Beijing
- 代理机构: Polsinelli PC
- 代理商 James M. Stipek; John R. Bednarz
- 优先权: CN201210551543 20121218
- 国际申请: PCT/CN2013/083667 WO 20130917
- 国际公布: WO2014/094470 WO 20140626
- 主分类号: H04L29/06
- IPC分类号: H04L29/06 ; H04L12/26 ; H04W4/00 ; G06F21/55 ; H04W12/12
摘要:
The present disclosure discloses a method, device and system for recognizing network behavior of a program. The method comprises: during the program's access to a network, acquiring application layer data in a current network behavior of the program; judging whether the application layer data includes an unknown protocol; if protocols in the application layer data are all known protocols, identifying the current network behavior of the program as a network behavior of a recognizable program; and if the application layer data includes an unknown protocol, identifying the current network behavior of the program as a network behavior of a suspicious program. As such, a accurate recognition of a network behavior of a program is realized, the network behavior of the program including an unknown protocol is identified as a network behavior of a suspicious program, risk prompt information can be sent to a user, and a final selection is performed by the user, thereby solving the problem that conventional solutions for recognizing a network behavior of a program cannot accurately recognize a network behavior of a newly-emerging or new variant program.
公开/授权文献
信息查询