发明名称 BLOCKING MALICIOUS ACTIVITY USING BLACKLIST
摘要 An IP (Internet Protocol) address is a directly observable identifier of host network traffic in the Internet and a host's IP address can dynamically change. Analysis of traffic (e.g., network activity or application request) logs may be performed and a host tracking graph may be generated that shows hosts and their bindings to IP addresses over time. A host tracking graph may be used to determine host accountability. This can enable host-based blacklisting instead of the traditional IP address based blacklisting. Host tracking results can be leveraged for forensic analysis to understand an attacker's traces and identify malicious activities in a postmortem fashion. The host tracking information may be used to build a tracklist which can block future attacks.
申请公布号 US2010313264(A1) 申请公布日期 2010.12.09
申请号 US20090479860 申请日期 2009.06.08
申请人 MICROSOFT CORPORATION 发明人 XIE YINGLIAN;YU FANG;ABADI MARTIN
分类号 G06F21/00 主分类号 G06F21/00
代理机构 代理人
主权项
地址