发明名称 SYSTEM AND METHOD FOR BOTNET DETECTION BY COMPREHENSIVE EMAIL BEHAVIORAL ANALYSIS
摘要 A method is provided in one example embodiment that includes receiving message sender traits associated with email senders, and receiving a dataset of known malware identifiers and network addresses from a spamtrap. The message sender traits may include behavior features and/or content resemblance factors in various embodiments. The method further includes classifying the email senders as malicious or benign based on the behavior features, and further classifying the malicious senders by malware identifiers based on similarity of content resemblance factors and the dataset of known malware identifiers and network addresses. In certain specific embodiments, a supervised classifier, such as a support vector machine, may be used to classify the malicious senders by malware identifiers.
申请公布号 US2013247192(A1) 申请公布日期 2013.09.19
申请号 US201113037988 申请日期 2011.03.01
申请人 KRASSER SVEN;TANG YUCHUN;ZHONG ZHENYU 发明人 KRASSER SVEN;TANG YUCHUN;ZHONG ZHENYU
分类号 G06F21/00 主分类号 G06F21/00
代理机构 代理人
主权项
地址