Invention Grant
- Patent Title: Detecting malicious beaconing communities using lockstep detection and co-occurrence graph
-
Application No.: US15626767Application Date: 2017-06-19
-
Publication No.: US10887323B2Publication Date: 2021-01-05
- Inventor: Jiyong Jang , Dhilung Hang Kirat , Bum Jun Kwon , Douglas Lee Schales , Marc Philippe Stoecklin
- Applicant: International Business Machines Corporation
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agency: McGinn IP Law Group, PLLC
- Agent Jeffrey S. LaBaw, Esq.
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06F21/55

Abstract:
A computer-implemented method (and apparatus) includes receiving input data comprising bipartite graph data in a format of source MAC (Machine Access Code) data versus destination IP (Internet Protocol) data and timestamp information. The input bipartite graph data is provided into a first processing to detect malicious beaconing activities using a lockstep detection method on the input bipartite graph data to detect possible synchronized attacks against a targeted infrastructure. The input bipartite graph data is also provided into a second processing, the second processing initially converting the bipartite graph data into a co-occurrence graph format that indicates in a graph format how devices in the targeted infrastructure communicate with different external destination servers over time. The second processing detects malicious beaconing activities by analyzing data exchanges with the external destination servers to detect anomalies.
Public/Granted literature
- US20180367547A1 DETECTING MALICIOUS BEACONING COMMUNITIES USING LOCKSTEP DETECTION AND CO-OCCURRENCE GRAPH Public/Granted day:2018-12-20
Information query