Patent · US Active

Detecting malware infestations in large-scale networks

US8959643B1 · kind B1 · utility

54Cited by
0References
9Claims
0Family size

Assignee

Inventors

Key dates

Filing dateAug 9, 2013
Grant dateFeb 17, 2015
Priority date
Expiry dateAug 15, 2033

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L63/1408
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

A method for detecting a malicious activity in a network. The method includes obtaining file download flows from the network, analyzing, the file download flows to generate malicious indications using a pre-determined malicious behavior detection algorithm, extracting a file download attribute from a suspicious file download flow of a malicious indication, wherein the file download attribute represents one or more of the URL, the FQDN, the top-level domain name, the URL path, the URL file name, and the payload of the suspicious file download flow, determining the file download attribute as being shared by at least two suspicious file download flows, identifying related suspicious file download flows and determining a level of association between based at least on the file download attribute, computing a malicious score of the suspicious file download flow based on the level of association, and presenting the malicious score to an analyst user of the network.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.