Invention Grant
- Patent Title: Live botmaster traceback
- Patent Title (中): Live botmaster追踪
-
Application No.: US12557993Application Date: 2009-09-11
-
Publication No.: US08176173B2Publication Date: 2012-05-08
- Inventor: Xinyuan Wang , Daniel Ramsbrock
- Applicant: Xinyuan Wang , Daniel Ramsbrock
- Applicant Address: US VA Fairfax
- Assignee: George Mason Intellectual Properties, Inc.
- Current Assignee: George Mason Intellectual Properties, Inc.
- Current Assignee Address: US VA Fairfax
- Agent David Grossman; David Yee
- Main IPC: G06F15/173
- IPC: G06F15/173

Abstract:
Embodiments locate a botmaster on a network. A honeynet host is configured to join a botnet and generate a watermarked packet flow by applying a watermark to an outgoing packet flow in response to commands from the botmaster. The watermark is applied to the outgoing packet flow by: choosing distinct packets from the outgoing packet flow; forming packet pair(s) from the distinct packets, that include a reference packet and an encoding packet; and encoding bits in the watermark to the packet pair(s) by increasing the length of the encoding packet when watermark bits have a predetermined value. The cooperating node(s) are configured to: inspect passing packet flows for the watermarked packet flow and generate tracking information related to detection of the watermarked packet flow. The path determination processor is configured to analyze the tracking information to locate a path taken by the watermarked packet flow.
Public/Granted literature
- US20100067377A1 Live Botmaster Traceback Public/Granted day:2010-03-18
Information query