Patent · US Active

Botnet detection and mitigation

US11627147B2 · kind B2 · utility

2Cited by
14References
21Claims
0Family size

Assignee

Inventors

Key dates

Filing dateMay 17, 2019
Grant dateApr 11, 2023
Priority date
Expiry dateJul 11, 2041

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L2463/144
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

Method and systems for detecting and mitigating a malicious bot. Threat information is obtained, the threat information identifying one or more indicators of compromise (IOC) corresponding to suspected or known malicious network traffic. A control list (CL) corresponding to the threat information is generated, the CL describing rules for identifying network flows to be logged in a network log. The network log identifying the network flows is obtained and a suspect network flow identified by both the threat information and the network log is identified. An address corresponding to the suspect network flow is identified and the address is correlated with a user identifier. A notification is issued to a user associated with the user identifier, the notification indicating a suspected existence of a malicious bot.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.