Invention Grant
US09407647B2 Method and system for detecting external control of compromised hosts 有权
用于检测受损主机的外部控制的方法和系统

Method and system for detecting external control of compromised hosts
Abstract:
A detection engine may be implemented by receiving network traffic and processing the traffic into one or more session datasets. Sessions not initiated by an internal host may be discarded. The frequency between the communication packets from the internal host to external host may be grouped or processed into rapid-exchange instances. The number of rapid-exchange instances, the time intervals between them, and/or the rhythm and directions of the initiation of the instances may be analyzed to determine that a human actor is manually controlling the external host. In some embodiments, when it is determined that only one human actor is involved, alarm data may be generated that indicates that a network intrusion involving manual remote control has occurred or is underway.
Information query
Patent Agency Ranking
0/0