Invention Grant
US09380071B2 Method for detection of persistent malware on a network node 有权
在网络节点上检测持久性恶意软件的方法

Method for detection of persistent malware on a network node
Abstract:
The present invention relates to methods and devices for detecting persistency of a first network node (12). In a first aspect of the invention, a method is provided comprising the steps of monitoring (S101), during a specified observation period, whether the first network node has established a connection to a second network node (13), and determining (S102) a total number of sessions of connectivity occurring during said specified observation period in which the first network node connects to the second network node. Further, the method comprises the steps of determining (S103), from the total number of sessions, a number of sessions comprising at least one communication flow between the first network node and the second network node, and determining (S104) inter-session persistence of the first network node on the basis of the total number of sessions and the number of sessions comprising at least one communication flow.
Public/Granted literature
Information query
Patent Agency Ranking
0/0