Periodicity detection of network traffic
US10671708B2 · kind B2 · utility
Assignee
Inventors
Key dates
| Filing date | Feb 11, 2019 |
| Grant date | Jun 2, 2020 |
| Priority date | — |
| Expiry date | Feb 11, 2039 |
Classification
- Technology area (CPC H)Electricity
- CPC primaryH04L67/535
- WIPO fieldDigital communication
- WIPO sectorElectrical engineering
Abstract
The improved detection of malicious processes executing on a networked computing device is provided. An agent running on the networked computing device monitors the communications transmitted to devices outside of the network to determine whether the process is likely using a periodic beacon signal to communicate with an external control center associated with a potentially malicious party. The agent maintains a dictionary data structure of objects, identifiable by the process identifier and the remote device's address, to track a given process/destination group's communication history. The communication history is updated when new messages are identified for periodic patterns to be identified for the messages, which may be used to identify a process as potentially malicious.
Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.