Invention Grant
- Patent Title: Structural command and control detection of polymorphic malware
-
Application No.: US16120580Application Date: 2018-09-04
-
Publication No.: US11038900B2Publication Date: 2021-06-15
- Inventor: Jan Jusko , Martin Rehak , Danila Khikhlukha , Harshit Nayyar
- Applicant: Cisco Technology, Inc.
- Applicant Address: US CA San Jose
- Assignee: Cisco Technology, Inc.
- Current Assignee: Cisco Technology, Inc.
- Current Assignee Address: US CA San Jose
- Agency: Behmke Innovation Group LLC
- Agent Kenneth J. Heywood; Jonathon P. Western
- Main IPC: H04L29/06
- IPC: H04L29/06

Abstract:
In one embodiment, a service receives a plurality of process hashes for processes executed by a plurality of devices. The service receives traffic data indicative of traffic between the plurality of devices and a plurality of remote server domains. The service forms a bipartite graph based on the processes hashes and the traffic data. A node of the graph represents a particular process hash or server domain and an edge between nodes in the graph represents network traffic between a process and a server domain. The service identifies, based on the bipartite graph, a subset of the plurality of processes as exhibiting polymorphic malware behavior. The service causes performance of a mitigation action in the network based on the identified subset of processes identified as exhibiting polymorphic malware behavior.
Public/Granted literature
- US20200076832A1 STRUCTURAL COMMAND AND CONTROL DETECTION OF POLYMORPHIC MALWARE Public/Granted day:2020-03-05
Information query