发明名称 METHOD AND DEVICE FOR DETECTING BOTNETS
摘要 A method and device for detecting the botnets are provided. The method involves that: acquiring a data message in a network, performing security analysis on the executable program in the data message, and determining the dangerous executable program to be a malicious resource; monitoring whether the malicious resource has an access requirement; if yes, determining the host sending out the access requirement as a bot. The technical proposal determines the host sending out the access requirement as the bot by actively acquiring the data message in the network, performing the security analysis on the executable program in the data message, and monitoring the address of the host which requires to access the dangerous executable program, thus actively determining the position of the bot before the network is under the attack of the botnet, and detecting the existing of the botnet.
申请公布号 WO2011000297(A1) 申请公布日期 2011.01.06
申请号 WO2010CN74611 申请日期 2010.06.28
申请人 CHENGDU HUAWEI SYMANTEC TECHNOLOGIES CO., LTD.;JIANG, WU 发明人 JIANG, WU
分类号 H04L12/26 主分类号 H04L12/26
代理机构 代理人
主权项
地址