发明名称 Method and apparatus for detecting compromised host computers
摘要 A method and apparatus for detecting compromised host computers (e.g., Bots) are disclosed. For example, the method identifies a plurality of suspicious hosts (102). Once identified, the method analyzes network traffic of the plurality suspicious hosts to identify a plurality of suspicious hub-servers. The method then classifies the plurality of candidate Bots into at least one group. The method then identifies members of each of the at least one group that are connected to a same controller (118) from the plurality suspicious controllers, where the members are identified to be part of a Botnet.
申请公布号 EP1906620(A1) 申请公布日期 2008.04.02
申请号 EP20070115453 申请日期 2007.08.31
申请人 AT&T CORP. 发明人 HOEFLIN, DAVID A.;KARASARIDIS, ANESTIS;REXROAD, CARL BRIAN
分类号 H04L29/06;G06F21/00 主分类号 H04L29/06
代理机构 代理人
主权项
地址
您可能感兴趣的专利