The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Aug. 28, 2018

Filed:

Apr. 30, 2013
Applicant:

Verint Systems Ltd., Herzelia, Pituach, IL;

Inventors:

Yuval Altman, Herzeliya, IL;

Assaf Yosef Kere, Ramat Gan, IL;

Ido Krupkin, Gan Yavne, IL;

Pinhas Rozenblum, Tzur Hadasa, IL;

Assignee:

Verint Systems Ltd., Herzelia, IL;

Attorney:
Primary Examiner:
Assistant Examiner:
Int. Cl.
CPC ...
G06F 21/56 (2013.01); H04L 29/06 (2006.01); G06F 21/52 (2013.01);
U.S. Cl.
CPC ...
G06F 21/56 (2013.01); G06F 21/52 (2013.01); G06F 21/566 (2013.01); H04L 63/1425 (2013.01);
Abstract

Systems and methods for malware detection techniques, which detect malware by identifying the C&C communication between the malware and the remote host. In particular, the disclosed techniques distinguish between request-response transactions that carry C&C communication and request-response transactions of innocent traffic. Individual request-response transactions may be analyzed rather than entire flows, and fine-granularity features examined within the transactions. As such, these methods and systems are highly effective in distinguishing between malware C&C communication and innocent traffic, i.e., in detecting malware with high detection probability and few false alarms.


Find Patent Forward Citations

Loading…