Patent · US Active

Monitoring for reverse-connection network activity to detect a remote-administration tool

US9961093B1 · kind B1 · utility

4Cited by
0References
22Claims
0Family size

Assignee

Inventor

Key dates

Filing dateSep 30, 2015
Grant dateMay 1, 2018
Priority date
Expiry dateJun 23, 2036

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L63/145
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

Techniques are disclosed for detecting malicious remote-administration tool (RAT) software by detecting reverse-connection communication activity. Communications are monitored over one or more persistent connections, such as TCP (Transmission Control Protocol) connections. Each monitored connection is between an initiator device and a follower device, and the initiator device is identified as the device that sent an initial packet to the follower device in order to open the connection. The disclosed techniques detect reverse-connection activity on the connection by detecting that communications over the connection are actually driven by the follower device, indicating that a malicious RAT is using the connection.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.