Invention Grant
- Patent Title: Prevention of rendezvous generation algorithm (RGA) and domain generation algorithm (DGA) malware over existing internet services
-
Application No.: US15296700Application Date: 2016-10-18
-
Publication No.: US10484422B2Publication Date: 2019-11-19
- Inventor: Uri Sternfeld , Yonatan Striem-Amit
- Applicant: Cybereason Inc.
- Applicant Address: US MA Boston
- Assignee: Cybereason, Inc.
- Current Assignee: Cybereason, Inc.
- Current Assignee Address: US MA Boston
- Agency: Flachsbart & Greenspoon LLC
- Agent Robert P. Greenspoon
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06F21/55 ; H04L29/08 ; G06F16/958 ; H04L29/12

Abstract:
A method, computer program product, system and apparatus for the prevention of RGA and DGA malware over an existing internet service is disclosed. The invention exploits the fact that when malware rapidly attempts to access many contact points, a malware is likely to need several attempts to find a current server. Software is installed on the individual endpoints in a network of internet services. The software monitors the websites or services and collects information about access attempts. The invention detects a series of failed attempts by the malware to access the service/website. These attempts can be accrued by being temporally linked (e.g., many attempts in a short time, many attempts consecutively), conceptually linked (e.g., similar addresses, similar attempts across multiple machines or time scales), higher than normal prevalence or other methods. The invention provides an indication of a malware attempt if enough failed attempts have accrued.
Public/Granted literature
- US20170195342A1 Prevention of RGA Over Existing Internet Services Public/Granted day:2017-07-06
Information query