Invention Grant
- Patent Title: Method for detection of persistent malware on a network node
- Patent Title (中): 在网络节点上检测持久性恶意软件的方法
-
Application No.: US14363484Application Date: 2012-04-02
-
Publication No.: US09380071B2Publication Date: 2016-06-28
- Inventor: Michael Liljenstam , András Méhes , Patrik Salmela
- Applicant: Michael Liljenstam , András Méhes , Patrik Salmela
- Applicant Address: SE Stockholm
- Assignee: Telefonaktiebolaget LM Ericsson (publ)
- Current Assignee: Telefonaktiebolaget LM Ericsson (publ)
- Current Assignee Address: SE Stockholm
- Agency: Murphy, Bilak & Homiller, PLLC
- International Application: PCT/SE2012/000048 WO 20120402
- International Announcement: WO2013/089607 WO 20130620
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04W12/12 ; H04L12/26 ; G06F21/56

Abstract:
The present invention relates to methods and devices for detecting persistency of a first network node (12). In a first aspect of the invention, a method is provided comprising the steps of monitoring (S101), during a specified observation period, whether the first network node has established a connection to a second network node (13), and determining (S102) a total number of sessions of connectivity occurring during said specified observation period in which the first network node connects to the second network node. Further, the method comprises the steps of determining (S103), from the total number of sessions, a number of sessions comprising at least one communication flow between the first network node and the second network node, and determining (S104) inter-session persistence of the first network node on the basis of the total number of sessions and the number of sessions comprising at least one communication flow.
Public/Granted literature
- US20150180898A1 Method for Detection of Persistent Malware on a Network Node Public/Granted day:2015-06-25
Information query