Invention Grant
- Patent Title: Utilizing clustering to identify IP addresses used by a botnet
-
Application No.: US16864350Application Date: 2020-05-01
-
Publication No.: US11652844B2Publication Date: 2023-05-16
- Inventor: Portase Nicuşor-Sorin , Cristian-Aurel Opincaru , Manole Catalin-Teodor
- Applicant: ADOBE INC.
- Applicant Address: US CA San Jose
- Assignee: ADOBE INC.
- Current Assignee: ADOBE INC.
- Current Assignee Address: US CA San Jose
- Agency: Shook, Hardy & Bacon L.L.P.
- Main IPC: H04L9/40
- IPC: H04L9/40

Abstract:
Methods and systems are provided for identifying suspect Internet Protocol (IP) addresses, in accordance with embodiments described herein. In particular, embodiments described herein include obtaining a set of login pairs comprising login identifiers (e.g., user identifiers) and IP addresses used in attempts to login to a source. A set of IP clusters is generated using the set of login pairs. Each IP cluster can include one or more IP addresses identified as related based on a login identifier being used to attempt to login to the source via multiple IP addresses or an IP address being used to attempt to login to the source via multiple login identifiers. Thereafter, it is determined that a particular IP cluster exceeds a threshold amount of IP addresses. Each of the IP addresses within the particular IP cluster is designated as a suspect IP address.
Public/Granted literature
- US20210344708A1 UTILIZING CLUSTERING TO IDENTIFY IP ADDRESSES USED BY A BOTNET Public/Granted day:2021-11-04
Information query