发明名称 SYSTEM AND METHOD FOR DETECTION OF DOMAIN-FLUX BOTNETS AND THE LIKE
摘要 In one embodiment, a method for detecting malicious software agents, such as domain-flux botnets. The method applies a co-clustering algorithm on a domain-name query failure graph, to generate a hierarchical grouping of hosts based on similarities between domain names queried by those hosts, and divides that hierarchical structure into candidate clusters based on percentages of failed queries having at least first- and second-level domain names in common, thereby identifying hosts having correlated queries as possibly being infected with malicious software agents. A linking algorithm is used to correlate the co-clustering results generated at different time periods to differentiate actual domain-flux bots from other domain-name failure anomalies by identifying candidate clusters that persist for relatively long periods of time. Persistent candidate clusters are analyzed to identify which clusters have malicious software agents, based on a freshness metric that characterizes whether the candidate clusters continually generate failed queries having new domain names.
申请公布号 US2012084860(A1) 申请公布日期 2012.04.05
申请号 US20100897494 申请日期 2010.10.04
申请人 CAO JIN;LI LI;JIANG NAN;ALCATEL-LUCENT USA INC. 发明人 CAO JIN;LI LI;JIANG NAN
分类号 G06F11/00 主分类号 G06F11/00
代理机构 代理人
主权项
地址