发明名称 Botmaster traceback
摘要 Embodiments locate a botmaster on a network. A honeynet host is configured to join a botnet and generate a watermarked packet flow by applying a watermark to an outgoing packet flow in response to commands from the botmaster. The watermark is applied to the outgoing packet flow by: choosing distinct packets from the outgoing packet flow; forming packet pair(s) from the distinct packets, that include a reference packet and an encoding packet; and encoding bits in the watermark to the packet pair(s) by increasing the length of the encoding packet when watermark bits have a predetermined value. The cooperating node(s) are configured to: inspect passing packet flows for the watermarked packet flow and generate tracking information related to detection of the watermarked packet flow. The path determination processor is configured to analyze the tracking information to locate a path taken by the watermarked packet flow.
申请公布号 US8433796(B2) 申请公布日期 2013.04.30
申请号 US201213441076 申请日期 2012.04.06
申请人 WANG XINYUAN;RAMSBROCK DANIEL;GEORGE MASON INTELLECTUAL PROPERTIES, INC. 发明人 WANG XINYUAN;RAMSBROCK DANIEL
分类号 G06F15/173 主分类号 G06F15/173
代理机构 代理人
主权项
地址