Invention Grant
- Patent Title: Periodicity detection of network traffic
-
Application No.: US16272830Application Date: 2019-02-11
-
Publication No.: US10671708B2Publication Date: 2020-06-02
- Inventor: Kyle Allan Reed , Matthew Michael Swann , Edward Chris Thayer
- Applicant: Microsoft Technology Licensing, LLC
- Applicant Address: US WA Redmond
- Assignee: Microsoft Technology Licensing, LLC
- Current Assignee: Microsoft Technology Licensing, LLC
- Current Assignee Address: US WA Redmond
- Agency: Newport IP, LLC
- Agent Han Gim
- Main IPC: G06F21/00
- IPC: G06F21/00 ; G06F21/56 ; H04L29/06 ; H04L29/08

Abstract:
The improved detection of malicious processes executing on a networked computing device is provided. An agent running on the networked computing device monitors the communications transmitted to devices outside of the network to determine whether the process is likely using a periodic beacon signal to communicate with an external control center associated with a potentially malicious party. The agent maintains a dictionary data structure of objects, identifiable by the process identifier and the remote device's address, to track a given process/destination group's communication history. The communication history is updated when new messages are identified for periodic patterns to be identified for the messages, which may be used to identify a process as potentially malicious.
Public/Granted literature
- US20190243947A1 PERIODICITY DETECTION OF NETWORK TRAFFIC Public/Granted day:2019-08-08
Information query