发明名称 System and Method for an NSP or ISP to Detect Malware in its Network Traffic
摘要 We show how a Network Service Provider (NSP) can detect if any of its customers are involved in malware. Like spamming or phishing. This involves the NSP's router performing a sampled packet analysis of outgoing and incoming messages. And combining this with our earlier methods for detecting spammer domain clusters (swarms) or phishing. Our method lets an NSP quickly shut down spammer customers, and reduces the risk that it and its innocent customers get blacklisted by other NSPs and ISPs. We use static and dynamic blacklists in the detection of spam/bulk messages in a message stream. Also, we use 3 sets of Bulk Message Envelopes (BMEs). A static set, which might be found from an Aggregation Center. A dynamic blacklisted BME set, which comes from messages hit by our blacklists. And a dynamic BME set that "good" bulk messages are put into. In tests, our method has programatically and consistently detected around 80% of sets of email messages as bulk/spam.
申请公布号 US2007124582(A1) 申请公布日期 2007.05.31
申请号 US20060462711 申请日期 2006.08.06
申请人 SHANNON MARVIN;BOUDVILLE WESLEY 发明人 SHANNON MARVIN;BOUDVILLE WESLEY
分类号 H04L9/00 主分类号 H04L9/00
代理机构 代理人
主权项
地址