发明名称 BOTTOM-UP ANALYSIS OF NETWORK SITES
摘要 An approach for identifying suspect network sites in a network environment entails using one or more malware analysis modules to identify distribution sites that host malicious content and/or benign content. The approach then uses a linking analysis module to identify landing sites that are linked to the distribution sites. These linked sites are identified as suspect sites for further analysis. This analysis can be characterized as “bottom up” because it is initiated by the detection of potentially problematic distribution sites. The approach can also perform linking analysis to identify a suspect network site based on a number of alternating paths between that network site and a set of distribution sites that are known to host malicious content. The approach can also train a classifier module to predict whether an unknown landing site is a malicious landing site or a benign landing site.
申请公布号 US2010262693(A1) 申请公布日期 2010.10.14
申请号 US20090421644 申请日期 2009.04.10
申请人 MICROSOFT CORPORATION 发明人 STOKES JACK W.;ANDERSEN REID M.;CHELLAPILLA KUMAR H.
分类号 G06F15/173 主分类号 G06F15/173
代理机构 代理人
主权项
地址