Invention Grant
- Patent Title: Firewall based botnet detection
- Patent Title (中): 基于防火墙的僵尸网络检测
-
Application No.: US13897519Application Date: 2013-05-20
-
Publication No.: US09124626B2Publication Date: 2015-09-01
- Inventor: Daniel E. Chapman, II , Gary I. Givental , John D. Kuhn , Michael J. Suzio
- Applicant: International Business Machines Corporation
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agent William H. Hartwell; Ian A. McKee
- Main IPC: H04L29/06
- IPC: H04L29/06

Abstract:
A computer detects malicious intrusions (or bots) into a computer. The computer receives firewall log data that includes communication records containing the source and destination of the communication, as well as, the time of the communication. The source or destination of the communication may be on a list of suspicious servers known to contain malicious software. The computer identifies a sequence of communications between a common source address and a common destination address. The computer further identifies substantially fixed intervals between the communications, and generates an alert indicating a suspected bot intrusion. The computer also identifies from the sequence of communication, patterns in the communication intervals, similarly generating an alert indicating a suspected bot intrusion.
Public/Granted literature
- US20140344912A1 FIREWALL BASED BOTNET DETECTION Public/Granted day:2014-11-20
Information query