Invention Grant
- Patent Title: Interception and policy application for malicious communications
- Patent Title (中): 用于恶意通信的拦截和策略应用
-
Application No.: US13928485Application Date: 2013-06-27
-
Publication No.: US09443075B2Publication Date: 2016-09-13
- Inventor: Stephen Ralph DiCato, Jr. , Daniel Kenneth Fayette , Todd Aaron O'Boyle
- Applicant: The MITRE Corporation
- Applicant Address: US VA McLean
- Assignee: The Mitre Corporation
- Current Assignee: The Mitre Corporation
- Current Assignee Address: US VA McLean
- Agency: Sterne, Kessler, Goldstein & Fox P.L.L.C.
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06F21/50

Abstract:
Disclosed herein are system, method, and computer program product embodiments for adapting to malware activity on a compromised computer system. An embodiment operates by detecting an adversary operating malware on a compromised system. A stream of network communications associated with adversary is intercepted. The stream of network communications includes a command and control channel of the adversary. The stream of network communications is accessed. An emulation of the command and control channel is provided. An analysis of the accessed stream of traffic is executed. A plurality of response mechanisms is provided. The plurality of response mechanisms is based in part on the analysis of the stream of network communications and a custom policy language tailored for the malware.
Public/Granted literature
- US20150007250A1 Interception and Policy Application for Malicious Communications Public/Granted day:2015-01-01
Information query