Patent · US Active

Periodicity detection of network traffic

US10204214B2 · kind B2 · utility

1Cited by
4References
20Claims
0Family size

Assignee

Inventors

Key dates

Filing dateSep 14, 2016
Grant dateFeb 12, 2019
Priority date
Expiry dateAug 10, 2037

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L67/535
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

The improved detection of malicious processes executing on a networked computing device is provided. An agent running on the networked computing device monitors the communications transmitted to devices outside of the network to determine whether the process is likely using a periodic beacon signal to communicate with an external control center associated with a potentially malicious party. The agent maintains a dictionary data structure of objects, identifiable by the process identifier and the remote device's address, to track a given process/destination group's communication history. The communication history is updated when new messages are identified for periodic patterns to be identified for the messages, which may be used to identify a process as potentially malicious.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.