发明名称 Method and system for statistical analysis of botnets
摘要 Systems and methods for determining whether a computer belongs to a botnet. Message parameter data for messages sent by a first computer is collected over a time period. A first set of distribution data representing a statistical distribution of the messages received from the first computer is generated, the statistical distribution being based on at least one message parameter of the message parameter data. The first set of distribution data is compared with a second set of distribution data corresponding to a statistical distribution of messages sent by a plurality of other computers over the same time period. Based on similarity between the first set of distribution data and at least a portion of the second set of distribution data, whether the first computer belongs to a botnet is determined.
申请公布号 EP2180660(A1) 申请公布日期 2010.04.28
申请号 EP20090251557 申请日期 2009.06.15
申请人 KASPERSKY LAB ZAO 发明人 BAKHMUTOV, ANDREY V
分类号 H04L29/06 主分类号 H04L29/06
代理机构 代理人
主权项
地址