Invention Grant
- Patent Title: Detection of botnet hosts using global encryption data
-
Application No.: US16251220Application Date: 2019-01-18
-
Publication No.: US11134073B2Publication Date: 2021-09-28
- Inventor: Thomas Manianghat Mathew , Dhia Mahjoub
- Applicant: Cisco Technology, inc.
- Applicant Address: US CA San Jose
- Assignee: Cisco Technology, inc.
- Current Assignee: Cisco Technology, inc.
- Current Assignee Address: US CA San Jose
- Agency: Behmke Innovation Group LLC
- Agent Kenneth J. Heywood; Jonathon P. Western
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04L29/12 ; H04L12/26 ; G06F17/16 ; H04L12/24

Abstract:
In one embodiment, a device obtains certificate information for a plurality of network addresses. The device constructs, based on the certificate information, a bipartite graph that maps nodes representing common names from the certificate information to nodes representing autonomous systems. The device determines edge counts from the bipartite graph for the nodes representing the autonomous systems. The device identifies, based on the edge counts, a particular one of the common names as botnet-related by comparing edge counts for the autonomous systems associated with that particular common name to edge counts for the autonomous systems associated with one or more of the other common names.
Public/Granted literature
- US20200036701A1 DETECTION OF BOTNET HOSTS USING GLOBAL ENCRYPTION DATA Public/Granted day:2020-01-30
Information query