Patent · US Active

Heuristic botnet detection

US9143522B2 · kind B2 · utility

19Cited by
36References
16Claims
0Family size

Assignee

Inventors

Key dates

Filing dateSep 4, 2013
Grant dateSep 22, 2015
Priority date
Expiry dateSep 4, 2033

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L2463/144
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

In some embodiments, heuristic botnet detection is provided. In some embodiments, heuristic botnet detection includes monitoring network traffic to identify suspicious network traffic; and detecting a bot based on a heuristic analysis of the suspicious network traffic behavior using a processor, in which the suspicious network traffic behavior includes command and control traffic associated with a bot master. In some embodiments, heuristic botnet detection further includes assigning a score to the monitored network traffic, in which the score corresponds to a botnet risk characterization of the monitored network traffic (e.g., based on one or more heuristic botnet detection techniques); increasing the score based on a correlation of additional suspicious behaviors associated with the monitored network traffic (e.g., based on one or more heuristic botnet detection techniques); and determining the suspicious behavior is associated with a botnet based on the score.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.