Invention Grant
- Patent Title: Method of and system for analysis of interaction patterns of malware with control centers for detection of cyber attack
-
Application No.: US15642529Application Date: 2017-07-06
-
Publication No.: US10430588B2Publication Date: 2019-10-01
- Inventor: Dmitry Aleksandrovich Volkov
- Applicant: TRUST LTD.
- Applicant Address: RU Moscow
- Assignee: TRUST LTD.
- Current Assignee: TRUST LTD.
- Current Assignee Address: RU Moscow
- Agency: BCF LLP
- Priority: RU2016127245 20160706
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06F21/56 ; G06F21/53 ; G06F21/55 ; H04L29/08

Abstract:
This technical solution relates to systems and methods of cyber attack detection, and more specifically it relates to analysis methods and systems for protocols of interaction of malware and cyber attack detection and control centers (servers). The method comprises: uploading the malware application into at least one virtual environment; collecting, by the server, a plurality of malware requests transmitted by the malware application to the malware control center; analyzing the plurality of malware requests to determine, for each given malware request: at least one malware request parameter contained therein; and an order thereof of the at least one malware request parameter. The method then groups the plurality of malware requests based on shared similar malware request parameters contained therein and order thereof and for each group of the at least one group containing at least two malware requests, generates a regular expression describing malware request parameters and order thereof of the group, which regular expression can be used as an emulator of the malware application.
Public/Granted literature
Information query