Invention Grant
- Patent Title: Botnet beaconing detection and mitigation
-
Application No.: US14838889Application Date: 2015-08-28
-
Publication No.: US10757136B2Publication Date: 2020-08-25
- Inventor: Yonatan Fridman , Kenneth J. Mckeever , Karl Stang
- Applicant: Verizon Patent and Licensing Inc.
- Applicant Address: US NJ Basking Ridge
- Assignee: Verizon Patent and Licensing Inc.
- Current Assignee: Verizon Patent and Licensing Inc.
- Current Assignee Address: US NJ Basking Ridge
- Main IPC: H04L29/06
- IPC: H04L29/06

Abstract:
A botnet detector collects data associated with flows between a pair of network elements. The botnet detector processes the flow data to determine whether some of the flows are associated with botnet beaconing and/or tunneling. For example, the botnet detector may determine whether some of the flows occur at a regular interval or whether some of the flows are associated with extended length sessions, respectively. To determine whether some of the flows occur at a regular interval, the botnet detector may convert the flow data to the frequency domain and may determine an interval associated with a highest vector magnitude. If the botnet detector determines that the pair of network elements are exchanging beaconing or tunneling signals, the botnet detector may forward a notification that the pair of network elements are associated with the botnet.
Public/Granted literature
- US20170063921A1 BOTNET BEACONING DETECTION AND MITIGATION Public/Granted day:2017-03-02
Information query