发明名称 IDENTIFYING MALWARE-INFECTED NETWORK DEVICES THROUGH TRAFFIC MONITORING
摘要 The present invention generally relates to detecting malicious network activity coming from network devices such as routers and firewalls. Specifically, embodiments of the present invention provide for detecting stealth malware on a network device by comparing inbound and outbound network traffic to discover packets originating from the network device and packets that violate configuration rules. When combined with a network traffic monitor server configured to monitor actual network traffic reports and to receive known network traffic reports from host computers, the system can detect stealth network traffic originating from both network devices and host computer systems.
申请公布号 WO2016014178(A1) 申请公布日期 2016.01.28
申请号 WO2015US36120 申请日期 2015.06.17
申请人 HEILIG, DAVID 发明人 HEILIG, DAVID
分类号 H04L29/06 主分类号 H04L29/06
代理机构 代理人
主权项
地址