Patent · US Active

Detection of malicious network connections

US9531742B2 · kind B2 · utility

11Cited by
2References
18Claims
0Family size

Assignee

Inventors

Key dates

Filing dateApr 10, 2016
Grant dateDec 27, 2016
Priority date
Expiry dateApr 10, 2036

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L63/1466
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

In one embodiment a method, system and apparatus is described for detecting a malicious network connection, the method system and apparatus including determining, for each connection over a network, if each connection is a persistent connection, if, as a result of the determining, a first connection is determined to be a persistent connection, collecting connection statistics for the first connection, creating a feature vector for the first connection based on the collected statistics, performing outlier detection for all of the feature vector for all connections over a network which have been determined to be persistent connections, and reporting detected outliers. Related methods, systems and apparatus are also described.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.