The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Feb. 25, 2020

Filed:

Aug. 03, 2017
Applicant:

Chunghwa Telecom Co., Ltd., Taoyuan, TW;

Inventors:

Tzung-Han Jeng, Taoyuan, TW;

Chien-Chih Chen, Taoyuan, TW;

Jia-Hao Sun, Taoyuan, TW;

Kuang-Hung Chang, Taoyuan, TW;

Kuo-Sen Chou, Taoyuan, TW;

Assignee:
Attorney:
Primary Examiner:
Assistant Examiner:
Int. Cl.
CPC ...
H04L 29/06 (2006.01); H04L 12/26 (2006.01); H04L 29/12 (2006.01);
U.S. Cl.
CPC ...
H04L 63/1483 (2013.01); H04L 43/16 (2013.01); H04L 63/14 (2013.01); H04L 63/1425 (2013.01); H04L 43/024 (2013.01); H04L 43/12 (2013.01); H04L 61/1511 (2013.01); H04L 2463/144 (2013.01); H04L 2463/146 (2013.01);
Abstract

A gateway apparatus, a detecting method of malicious domain and hacked host thereof, and a non-transitory computer readable medium are provided. The detecting method includes the following steps: capturing network traffics, and parsing traces and channels from the network traffics. Each channel is related to a link between a domain and an Internet Protocol (IP) address, and each trace is related to an http request requested from the IP address for asking the domain. Then, a trace-channel behavior graph is established. The malicious degree model is trained based on the trace-channel behavior graph and threat intelligence. Accordingly, a malicious degree of an unknown channel can be determined, thereby providing a detecting method with high precision.


Find Patent Forward Citations

Loading…