METHOD FOR DETECTION OF PERSISTENT MALWARE ON A NETWORK NODE
    3.
    发明公开
    METHOD FOR DETECTION OF PERSISTENT MALWARE ON A NETWORK NODE 审中-公开
    检测方法的有害持久性对网络节点

    公开(公告)号:EP2792178A4

    公开(公告)日:2015-09-02

    申请号:EP12857467

    申请日:2012-04-02

    Abstract: The present invention relates to methods and devices for detecting persistency of a first network node (12). In a first aspect of the invention, a method is provided comprising the steps of monitoring (S101), during a specified observation period, whether the first network node has established a connection to a second network node (13), and determining (S102) a total number of sessions of connectivity occurring during said specified observation period in which the first network node connects to the second network node. Further, the method comprises the steps of determining (S103), from the total number of sessions, a number of sessions comprising at least one communication flow between the first network node and the second network node, and determining (S104) inter-session persistence of the first network node on the basis of the total number of sessions and the number of sessions comprising at least one communication flow.

Patent Agency Ranking