Invention Grant
- Patent Title: Blocking malicious activity using blacklist
- Patent Title (中): 使用黑名单阻止恶意活动
-
Application No.: US12479860Application Date: 2009-06-08
-
Publication No.: US08387145B2Publication Date: 2013-02-26
- Inventor: Yinglian Xie , Fang Yu , Martin Abadi
- Applicant: Yinglian Xie , Fang Yu , Martin Abadi
- Applicant Address: US WA Redmond
- Assignee: Microsoft Corporation
- Current Assignee: Microsoft Corporation
- Current Assignee Address: US WA Redmond
- Agency: Microsoft Corporation
- Main IPC: G06F12/14
- IPC: G06F12/14 ; G06F12/16

Abstract:
An IP (Internet Protocol) address is a directly observable identifier of host network traffic in the Internet and a host's IP address can dynamically change. Analysis of traffic (e.g., network activity or application request) logs may be performed and a host tracking graph may be generated that shows hosts and their bindings to IP addresses over time. A host tracking graph may be used to determine host accountability. This can enable host-based blacklisting instead of the traditional IP address based blacklisting. Host tracking results can be leveraged for forensic analysis to understand an attacker's traces and identify malicious activities in a postmortem fashion. The host tracking information may be used to build a tracklist which can block future attacks.
Public/Granted literature
- US20100313264A1 BLOCKING MALICIOUS ACTIVITY USING BLACKLIST Public/Granted day:2010-12-09
Information query