发明名称 Determination Of Participation In A Malicious Software Campaign
摘要 Sources of spam, such as botnets, are detected by analyzing message traffic for behavioral patterns and indications of suspicious content. The content of a known malicious source is analyzed. Message traffic associated with the known malicious source is analyzed. Associated message traffic includes messages sent directly from the known malicious source to recipients, and messages sent from the recipients to subsequent direct and indirect recipients. Portions of the content of the known malicious source are selected and content of associated message traffic is analyzed for an indication of the selected content. If the selected content is found in the content of a message, the source of the message is determined to be a source of spam. Associated message traffic is additionally analyzed for behavioral patterns, such as anomalies and/or flurries of activity, to determine a potential malicious source.
申请公布号 US2008320095(A1) 申请公布日期 2008.12.25
申请号 US20070767860 申请日期 2007.06.25
申请人 MICROSOFT CORPORATION 发明人 PEARSON MALCOLM ERIK;COSTEA MIHAI
分类号 G06F15/16 主分类号 G06F15/16
代理机构 代理人
主权项
地址