发明名称 Software network behavior analysis and identification system
摘要 A particular method includes detecting, at a detection module, an indicator corresponding to a suspicious software component, where the indicator is detected based on monitored network data of a network system and based on a plurality of network behavior profiles. At least one of the network behavior profiles includes an ordered sequence of network actions. The method further includes determining, at an identification module, whether the indicator corresponds to any of the plurality of network behavior profiles. The method further includes generating output data in response to a determination that the indicator corresponds to a particular network behavior profile of the plurality of network behavior profiles.
申请公布号 EP2854362(A1) 申请公布日期 2015.04.01
申请号 EP20140179336 申请日期 2014.07.31
申请人 THE BOEING COMPANY 发明人 DAVIS, AARON R.;ALDRICH, TIMOTHY M.;BIALEK, MATTHEW S.;LEMM, TIMOTHY M.;KOSPIAH, SHAUN
分类号 H04L29/06 主分类号 H04L29/06
代理机构 代理人
主权项
地址