首页> 外国专利> TECHNIQUES FOR TARGETED BOTNET PROTECTION USING COLLECTIVE BOTNET ANALYSIS

TECHNIQUES FOR TARGETED BOTNET PROTECTION USING COLLECTIVE BOTNET ANALYSIS

机译:基于集体僵尸网络分析的目标僵尸网络保护技术

摘要

A botnet identification module identifies members of one or more botnets based upon network traffic destined to one or more servers over time, and provides sets of botnet sources to a traffic monitoring module. Each set of botnet sources includes a plurality of source identifiers of end stations acting as part of a corresponding botnet. A traffic monitoring module receives the sets of botnet sources from the botnet identification module, and upon a receipt of traffic identified as malicious that was sent by a source identified within one of the sets of botnet sources, activates a protection mechanism with regard to all traffic from all of the sources identified by the one of the sets of botnet sources for an amount of time.
机译:僵尸网络识别模块根据一段时间内发往一个或多个服务器的网络流量来识别一个或多个僵尸网络的成员,并将僵尸网络源集提供给流量监视模块。每组僵尸网络源均包括充当相应僵尸网络一部分的终端站的多个源标识符。流量监控模块从僵尸网络标识模块接收僵尸网络源集,并在接收到由一组僵尸网络源之一中标识的源发送的被识别为恶意的流量后,针对所有流量激活保护机制从一组僵尸网络源之一标识的所有源中获取一定时间。

著录项

  • 公开/公告号US2017251016A1

    专利类型

  • 公开/公告日2017-08-31

    原文格式PDF

  • 申请/专利权人 IMPERVA INC.;

    申请/专利号US201715442571

  • 发明设计人 NITZAN NIV;AMICHAI SHULMAN;

    申请日2017-02-24

  • 分类号H04L29/06;H04L12/26;

  • 国家 US

  • 入库时间 2022-08-21 13:48:58

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号