Invention Grant
- Patent Title: Detection of botnets using command-and-control access patterns
-
Application No.: US15362076Application Date: 2016-11-28
-
Publication No.: US10594711B2Publication Date: 2020-03-17
- Inventor: Roy Levin , Royi Ronen
- Applicant: Microsoft Technology Licensing, LLC.
- Applicant Address: US WA Redmond
- Assignee: MICROSOFT TECHNOLOGY LICENSING, LLC.
- Current Assignee: MICROSOFT TECHNOLOGY LICENSING, LLC.
- Current Assignee Address: US WA Redmond
- Agency: M&B IP Analysts, LLC
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06F9/455 ; G06N20/00 ; H04L29/08

Abstract:
A method and device for detecting botnets in a cloud-computing infrastructure are provided. The method includes gathering data feeds over a predefined detection time window to produce a detection dataset, wherein the detection dataset includes at least security events and a first set of bot-labels related to the activity of each of at least one virtual machine in the cloud-computing infrastructure during the detection time window; generating, using the detection dataset, a features vector for each of a plurality of virtual machines in the cloud-computing infrastructure, wherein the features vector is based on idiosyncratic (iSync) scores related to botnet activity; transmitting each generated features vector to a supervised machine learning decision model to generate a label indicating if each of the plurality of virtual machines is a bot based on the respective features vector; and determining each virtual machine labeled as a bot as being part of a botnet.
Public/Granted literature
- US20180152465A1 DETECTION OF BOTNETS USING COMMAND-AND-CONTROL ACCESS PATTERNS Public/Granted day:2018-05-31
Information query