发明名称 DETECTING MALICIOUS BEHAVIOUR ON A COMPUTER NETWORK
摘要 A malicious behaviour detector (100) for detecting malicious behaviour on a network, comprises a processor unit (120) and associated system memory (130) containing computer program code. The computer program code provides a signature matching module (132) to perform malicious partial signature detection by reading the contents of packets of data passing through the network to look for partial signatures associated with malicious programs; a Domain Name Service, DNS, request and/or response detection module (134) to monitor the requests made by hosts connected to the network and/or responses thereto; and an evidence assessment module (138) to analyse the results of the partial signature detection and the DNS monitoring make a determination of the suspected presence of malicious behaviour on the network based upon the analysis of the results of both the partial signature detection and the DNS monitoring.
申请公布号 WO2010097575(A1) 申请公布日期 2010.09.02
申请号 WO2010GB00322 申请日期 2010.02.23
申请人 BRITISH TELECOMMUNICATIONS PUBLIC LIMITED COMPANY;EL-MOUSSA, FADI 发明人 EL-MOUSSA, FADI
分类号 H04L29/06;H04L12/26 主分类号 H04L29/06
代理机构 代理人
主权项
地址