Invention Grant
- Patent Title: Malicious host detection
-
Application No.: US16636278Application Date: 2018-07-30
-
Publication No.: US11621976B2Publication Date: 2023-04-04
- Inventor: Fadi El-Moussa , George Kallos
- Applicant: British Telecommunications Public Limited Company
- Applicant Address: GB London
- Assignee: British Telecommunications Public Limited Company
- Current Assignee: British Telecommunications Public Limited Company
- Current Assignee Address: GB London
- Agency: Patterson Thuente, P.A.
- Priority: EP17184579 20170802
- International Application: PCT/EP2018/070630 WO 20180730
- International Announcement: WO2019/025384 WO 20190207
- Main IPC: H04L9/40
- IPC: H04L9/40 ; G06N3/04 ; G06N3/088

Abstract:
A method for detecting malware software in a computer system includes accessing a plurality of hostnames for a malware server from a computer system infected with malware and attempting to communicate with the malware server, each hostname including a plurality of symbols in each of a plurality of symbol positions; training an autoencoder based on each of the plurality of hostnames, wherein the autoencoder includes: a set of input units for each possible symbol and symbol position in a hostname; output units each for storing an output of the autoencoder; and a set of hidden units smaller in number than the set of input units and each interconnecting all input and all output units with weighted interconnections, such that the autoencoder is trainable to provide an approximated reconstruction of values of the input units at the output units; selecting a set of one or more symbol and symbol position tuples based on weights of interconnections in the trained autoencoder; and identifying infected computer systems based on their attempted communication to hostnames having symbols in symbol positions consistent with the tuples in the set.
Public/Granted literature
- US20200228544A1 MALICIOUS HOST DETECTION Public/Granted day:2020-07-16
Information query