Invention Grant
- Patent Title: Classification of malware generated domain names
-
Application No.: US14633805Application Date: 2015-02-27
-
Publication No.: US09602525B2Publication Date: 2017-03-21
- Inventor: Jiang Qian , Adam J. O'Donnell , Paul Frank , Patrick Mullen
- Applicant: Cisco Technology, Inc.
- Applicant Address: US CA San Jose
- Assignee: Cisco Technology, Inc.
- Current Assignee: Cisco Technology, Inc.
- Current Assignee Address: US CA San Jose
- Agency: Edell, Shapiro & Finnan, LLC
- Main IPC: G06F12/14
- IPC: G06F12/14 ; H04L29/06

Abstract:
Techniques are presented herein that combine a host-based analysis of an executable file on a host computer with a network-based analysis, i.e., an analysis of domain names to detect malware generated domain names that are used by the malicious executable files to establish malicious network connections. A server receives information from a host computer about an executable file that, when executed on the host computer, initiates a network connection. The server also receives information about the network connection itself. The server analyzes the information about the executable file to determine whether the executable file has a malicious disposition. Depending on a disposition of the executable file, the server analyzes the information about the network connection and determines whether the network connection is malicious.
Public/Granted literature
- US20160255107A1 Classification of Malware Generated Domain Names Public/Granted day:2016-09-01
Information query