发明名称 Machine learning based botnet detection using real-time extracted traffic features
摘要 A method for identifying a botnet in a network, including analyzing historical network data using a pre-determined heuristic to determine values of a feature in the historical network data, obtaining a ground truth data set having labels assigned to data units in the historical network data identifying known malicious nodes in the network, analyzing the historical network data and the ground truth data set using a machine learning algorithm to generate a model representing the labels as a function of the values of the feature, analyzing real-time network data using the pre-determined heuristic to determine a value of the feature for a data unit in the real-time network data, assigning a label to the data unit by applying the model to the value of the feature, and categorizing the data unit as associated with the botnet based on the label.
申请公布号 US8682812(B1) 申请公布日期 2014.03.25
申请号 US20100978378 申请日期 2010.12.23
申请人 RANJAN SUPRANAMAYA;NARUS, INC. 发明人 RANJAN SUPRANAMAYA
分类号 G06N7/00;G06F15/18;H04L12/24;H04L29/06;H04L29/14 主分类号 G06N7/00
代理机构 代理人
主权项
地址