Invention Grant
US08682812B1 Machine learning based botnet detection using real-time extracted traffic features
有权
基于机器学习的僵尸网络检测使用实时提取的流量特征
- Patent Title: Machine learning based botnet detection using real-time extracted traffic features
- Patent Title (中): 基于机器学习的僵尸网络检测使用实时提取的流量特征
-
Application No.: US12978378Application Date: 2010-12-23
-
Publication No.: US08682812B1Publication Date: 2014-03-25
- Inventor: Supranamaya Ranjan
- Applicant: Supranamaya Ranjan
- Applicant Address: US CA Sunnyvale
- Assignee: Narus, Inc.
- Current Assignee: Narus, Inc.
- Current Assignee Address: US CA Sunnyvale
- Agency: Fernandez & Associates, LLP
- Main IPC: G06N7/00
- IPC: G06N7/00 ; H04L29/14 ; G06F15/18 ; H04L12/24 ; H04L29/06

Abstract:
A method for identifying a botnet in a network, including analyzing historical network data using a pre-determined heuristic to determine values of a feature in the historical network data, obtaining a ground truth data set having labels assigned to data units in the historical network data identifying known malicious nodes in the network, analyzing the historical network data and the ground truth data set using a machine learning algorithm to generate a model representing the labels as a function of the values of the feature, analyzing real-time network data using the pre-determined heuristic to determine a value of the feature for a data unit in the real-time network data, assigning a label to the data unit by applying the model to the value of the feature, and categorizing the data unit as associated with the botnet based on the label.
Information query
IPC分类:
G | 物理 |
G06 | 计算;推算或计数 |
G06N | 基于特定计算模型的计算机系统 |
G06N7/00 | 基于特定数学模式的计算机系统 |