Patent · US Active

Detecting malicious network software agents

US9344445B2 · kind B2 · utility

25Cited by
17References
19Claims
0Family size

Assignee

Inventors

Key dates

Filing dateDec 15, 2014
Grant dateMay 17, 2016
Priority date
Expiry dateDec 15, 2034

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L2463/144
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

This disclosure describes techniques for determining whether a network session originates from an automated software agent. In one example, a network device, such as a router, includes a network interface to receive packets of a network session, a bot detection module to calculate a plurality of scores for network session data based on a plurality of metrics, wherein each of the metrics corresponds to a characteristic of a network session originated by an automated software agent, to produce an aggregate score from an aggregate of the plurality of scores, and to determine that the network session is originated by an automated software agent when the aggregate score exceeds a threshold, and an attack detection module to perform a programmed response when the network session is determined to be originated by an automated software agent. Each score represents a likelihood that the network session is originated by an automated software agent.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.