Invention Grant
- Patent Title: Method, apparatus and system for detecting botnet
- Patent Title (中): 检测僵尸网络的方法,装置和系统
-
Application No.: US13452214Application Date: 2012-04-20
-
Publication No.: US08904532B2Publication Date: 2014-12-02
- Inventor: Wu Jiang
- Applicant: Wu Jiang
- Applicant Address: CN Chengdu
- Assignee: Chengdu Huawei Symantec Technologies Co., Ltd.
- Current Assignee: Chengdu Huawei Symantec Technologies Co., Ltd.
- Current Assignee Address: CN Chengdu
- Agency: Leydig, Voit & Mayer, Ltd.
- Priority: CN200910206068 20091020
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04L12/24

Abstract:
A method, an apparatus, and a system for detecting Botnet are disclosed. The method for detecting Botnet includes: obtaining an address information about a control host in a Bot sample by using an auto breakout environment; sending a query request message to a traffic analysis device to obtain an address information of a Bot host connected with the control host, in which the query request message carries the address information about the control host; and receiving a query response message returned by the traffic analysis device, in which the query response message carries the address information of the Bot host connected with the control host. The method for detecting Botnet can obtain the Botnet information in real time and construct a topology of the Botnet.
Public/Granted literature
- US20120204264A1 METHOD, APPARATUS AND SYSTEM FOR DETECTING BOTNET Public/Granted day:2012-08-09
Information query