The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Jun. 24, 2014

Filed:

Jan. 05, 2011
Applicants:

Supranamaya Ranjan, Albany, CA (US);

Joshua Robinson, San Francisco, CA (US);

Feilong Chen, East Lansing, MI (US);

Inventors:

Supranamaya Ranjan, Albany, CA (US);

Joshua Robinson, San Francisco, CA (US);

Feilong Chen, East Lansing, MI (US);

Assignee:

Narus, Inc., Sunnyvale, CA (US);

Attorney:
Primary Examiner:
Assistant Examiner:
Int. Cl.
CPC ...
G06N 5/02 (2006.01); G06N 99/00 (2010.01); H04L 1/00 (2006.01); H04L 29/06 (2006.01);
U.S. Cl.
CPC ...
G06N 5/02 (2013.01); G06N 99/005 (2013.01); H04L 63/14 (2013.01);
Abstract

A method for identifying a botnet in a network, including analyzing historical network data using a pre-determined heuristic to determine values of a connectivity graph based feature in the historical network data, obtaining a ground truth data set having labels assigned to data units in the historical network data identifying known malicious nodes in the network, analyzing the historical network data and the ground truth data set using a machine learning algorithm to generate a model representing the labels as a function of the values of the connectivity graph based feature, analyzing real-time network data using the pre-determined heuristic to determine a value of the connectivity graph based feature for a data unit in the real-time network data, assigning a label to the data unit by applying the model to the value of the connectivity graph based feature, and categorizing the data unit as associated with the botnet based on the label.


Find Patent Forward Citations

Loading…