Invention Grant
- Patent Title: Monitoring for reverse-connection network activity to detect a remote-administration tool
-
Application No.: US14870492Application Date: 2015-09-30
-
Publication No.: US09961093B1Publication Date: 2018-05-01
- Inventor: Andreas Wittenstein
- Applicant: EMC Corporation
- Applicant Address: US MA Hopkinton
- Assignee: EMC IP Holding Company LLC
- Current Assignee: EMC IP Holding Company LLC
- Current Assignee Address: US MA Hopkinton
- Agency: BainwoodHuang
- Main IPC: G06F17/00
- IPC: G06F17/00 ; H04L29/06

Abstract:
Techniques are disclosed for detecting malicious remote-administration tool (RAT) software by detecting reverse-connection communication activity. Communications are monitored over one or more persistent connections, such as TCP (Transmission Control Protocol) connections. Each monitored connection is between an initiator device and a follower device, and the initiator device is identified as the device that sent an initial packet to the follower device in order to open the connection. The disclosed techniques detect reverse-connection activity on the connection by detecting that communications over the connection are actually driven by the follower device, indicating that a malicious RAT is using the connection.
Information query