Invention Grant
- Patent Title: Determination of participation in a malicious software campaign
- Patent Title (中): 决定参与恶意软件运动
-
Application No.: US11767860Application Date: 2007-06-25
-
Publication No.: US07899870B2Publication Date: 2011-03-01
- Inventor: Malcolm Erik Pearson , Mihai Costea
- Applicant: Malcolm Erik Pearson , Mihai Costea
- Applicant Address: US WA Redmond
- Assignee: Microsoft Corporation
- Current Assignee: Microsoft Corporation
- Current Assignee Address: US WA Redmond
- Agency: Woodcock Washburn LLP
- Main IPC: G06F15/16
- IPC: G06F15/16

Abstract:
Sources of spam, such as botnets, are detected by analyzing message traffic for behavioral patterns and indications of suspicious content. The content of a known malicious source is analyzed. Message traffic associated with the known malicious source is analyzed. Associated message traffic includes messages sent directly from the known malicious source to recipients, and messages sent from the recipients to subsequent direct and indirect recipients. Portions of the content of the known malicious source are selected and content of associated message traffic is analyzed for an indication of the selected content. If the selected content is found in the content of a message, the source of the message is determined to be a source of spam. Associated message traffic is additionally analyzed for behavioral patterns, such as anomalies and/or flurries of activity, to determine a potential malicious source.
Public/Granted literature
- US20080320095A1 Determination Of Participation In A Malicious Software Campaign Public/Granted day:2008-12-25
Information query