The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Jun. 28, 2022

Filed:

Jul. 18, 2018
Applicant:

Shenzhen Leagsoft Technology Co., Ltd., Shenzhen, CN;

Inventors:

Ming Du, Shenzhen, CN;

Dazhi Tu, Shenzhen, CN;

Xincheng Wang, Shenzhen, CN;

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
G06F 15/16 (2006.01); H04L 61/4511 (2022.01); G06N 3/02 (2006.01); G06N 7/00 (2006.01); H04L 9/40 (2022.01);
U.S. Cl.
CPC ...
H04L 61/1511 (2013.01); G06N 3/02 (2013.01); G06N 7/005 (2013.01); H04L 63/1491 (2013.01);
Abstract

The invention provides a command-and-control (C&C) domain name analysis-based botnet detection method, device, apparatus and medium. The method includes an information acquisition step where DNS logs are acquired; a domain name analysis step where C&C domain names in the DNS logs are detected and the category of each C&C domain name is determined according to a pre-built domain name analyzer; a botnet determination step where whether a botnet exists is determined according to the C&C domain name and the category of C&C domain name. In the C&C domain name analysis-based botnet detection method, device, apparatus and medium provided by the present invention, by analyzing the domain name system (DNS) logs, the C&C domain name used in the attack activity is extracted for further analysis of the types of parasitic Trojans to thereby lock down the bot that the C&C server has controlled. In addition, the botnet activity trend can be analyzed by analyzing the Poisson parameter of each type of the C&C domain name, so as to form effective suppression measures in time.


Find Patent Forward Citations

Loading…