发明名称 SYSTEM AND METHOD FOR DETECTING A MALICIOUS COMMAND AND CONTROL CHANNEL
摘要 <p>A method is provided in one example embodiment that includes detecting repetitive connections from a source node to a destination node, calculating a score for the source node based on the connections, and taking a policy action if the score exceeds a threshold score. In more particular embodiments, the repetitive connections use a hypertext transfer protocol and may include connections to a small number of unique domains, connections to small number of unique resources associated with the destination node, and/or a large number of connections to a resource in a domain. Moreover, heuristics may be used to score the source node and identify behavior indicative of a threat, such as a bot or other malware.</p>
申请公布号 EP2774070(A4) 申请公布日期 2015.03.11
申请号 EP20120842148 申请日期 2012.09.28
申请人 MCAFEE, INC. 发明人 BALUPARI, RAVINDRA H.;MAHADIK, VINAY;MADHUSUDAN, BHARATH;SHAH, CHINTAN H.
分类号 G06F21/00;G06F11/30;G06F21/55;H04L29/06 主分类号 G06F21/00
代理机构 代理人
主权项
地址