发明名称 Classification of malware generated domain names
摘要 Techniques are presented herein that combine a host-based analysis of an executable file on a host computer with a network-based analysis, i.e., an analysis of domain names to detect malware generated domain names that are used by the malicious executable files to establish malicious network connections. A server receives information from a host computer about an executable file that, when executed on the host computer, initiates a network connection. The server also receives information about the network connection itself. The server analyzes the information about the executable file to determine whether the executable file has a malicious disposition. Depending on a disposition of the executable file, the server analyzes the information about the network connection and determines whether the network connection is malicious.
申请公布号 US9602525(B2) 申请公布日期 2017.03.21
申请号 US201514633805 申请日期 2015.02.27
申请人 Cisco Technology, Inc. 发明人 Qian Jiang;O'Donnell Adam J.;Frank Paul;Mullen Patrick
分类号 G06F12/14;H04L29/06 主分类号 G06F12/14
代理机构 Edell, Shapiro & Finnan, LLC 代理人 Edell, Shapiro & Finnan, LLC
主权项 1. A method comprising: receiving information about an executable file residing on a host computer that, when executed on the host computer, initiates a network connection; receiving information about the network connection, including a domain name included in network traffic associated with the network connection; analyzing the information about the executable file to determine whether the executable file has an unknown disposition; upon determining that the executable file has the unknown disposition, analyzing the information about the network connection to determine whether the network connection is malicious based on whether the domain name is generated by a domain generation algorithm; and classifying the network connection as being malicious when it is determined that the domain name is generated by the domain generation algorithm.
地址 San Jose CA US