Invention Grant
- Patent Title: Detection of beaconing behavior in network traffic
- Patent Title (中): 网络流量中信标行为的检测
-
Application No.: US14668595Application Date: 2015-03-25
-
Publication No.: US09591007B2Publication Date: 2017-03-07
- Inventor: Xin Hu , Jiyong Jang , Douglas Schales , Marc Stoecklin , Ting Wang
- Applicant: International Business Machines Corporation
- Applicant Address: US NY Armonk
- Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
- Current Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
- Current Assignee Address: US NY Armonk
- Agency: McGinn IP Law Group, PLLC
- Agent Jeff LaBaw, Esq.
- Main IPC: H04L29/06
- IPC: H04L29/06

Abstract:
A method for detecting beaconing behavior includes preprocessing network records to identify candidate source and destination pairs for detecting beaconing behavior, where each source and destination pair is associated with a specific time interval in a plurality of time intervals forming a time range, the time interval and time range having been predefined. The activity time interval information is converted from the time domain into the frequency domain. Candidate frequencies are determined from the source and destination pairs, as likely candidate frequencies/periodicities of beaconing activities.
Public/Granted literature
- US20160134641A1 DETECTION OF BEACONING BEHAVIOR IN NETWORK TRAFFIC Public/Granted day:2016-05-12
Information query