- 专利标题: Systems and methods for identifying message payload bit fields in electronic communications
-
申请号: US15359076申请日: 2016-11-22
-
公开(公告)号: US09906545B1公开(公告)日: 2018-02-27
- 发明人: Zhipeng Zhao , Michael Pukish , Chaopin Zhu , Preeti Agarwal
- 申请人: Symantec Corporation
- 申请人地址: US CA Mountain View
- 专利权人: Symantec Corporation
- 当前专利权人: Symantec Corporation
- 当前专利权人地址: US CA Mountain View
- 代理机构: FisherBroyles, LLP
- 主分类号: G06F11/00
- IPC分类号: G06F11/00 ; H04L29/06
摘要:
The disclosed computer-implemented method for identifying message payload bit fields in electronic communications may include (i) monitoring messages transmitted via a network, (ii) selecting a plurality of messages transmitted via the network, each of the plurality of messages comprising an identical message identifier corresponding to a specified message type having a payload, (iii) determining for each bit position in the payload of the specified message type, a quasi-entropy value based on a proportion of occurrences of a first bit value and a proportion of occurrences of a second bit value at each corresponding bit position in the plurality of messages, and (iv) identifying at least one of a near-random bit field, a periodic bit field, and a constant bit field within the specified message type based on the determined quasi-entropy values. Various other methods, systems, and computer-readable media are also disclosed.
信息查询