Invention Grant
- Patent Title: Distributed system for Bot detection
-
Application No.: US14458026Application Date: 2014-08-12
-
Publication No.: US09769204B2Publication Date: 2017-09-19
- Inventor: Venu Vissamsetty , Shivakumar Buruganahalli
- Applicant: Attivo Networks Inc.
- Applicant Address: US CA Fremont
- Assignee: Attivo Networks Inc.
- Current Assignee: Attivo Networks Inc.
- Current Assignee Address: US CA Fremont
- Agency: Stevens Law Group
- Agent David R. Stevens
- Main IPC: H04L29/06
- IPC: H04L29/06

Abstract:
A system includes one or more “BotMagnet” modules that are exposed to infection by malicious code. The BotMagnets may include one or more virtual machines hosing operating systems in which malicious code may be installed and executed without exposing sensitive data or other parts of a network. In particular, outbound traffic may be transmitted to a Sinkhole module that implements a service requested by the outbound traffic and transmits responses to the malicious code executing within the BotMagnet. The Sinkhole module may implement a proxy mode in which traffic received by the Sinkhole module is transmitted to a destination specified in the traffic but modified to reference the Sinkhole as the source. Events occurring on the BotMagnet and Sinkhole are correlated and used to characterize the malicious code. The characterization may be transmitted to other computer systems in order to detect instances of the malicious code.
Public/Granted literature
- US20150326587A1 DISTRIBUTED SYSTEM FOR BOT DETECTION Public/Granted day:2015-11-12
Information query