Invention Grant
- Patent Title: Identifying malicious executables by analyzing proxy logs
-
Application No.: US15040285Application Date: 2016-02-10
-
Publication No.: US09992216B2Publication Date: 2018-06-05
- Inventor: Tomas Pevny , Petr Somol
- Applicant: Cisco Technology, Inc.
- Applicant Address: US CA San Jose
- Assignee: Cisco Technology, Inc.
- Current Assignee: Cisco Technology, Inc.
- Current Assignee Address: US CA San Jose
- Agency: Edell, Shapiro & Finnan, LLC
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06F21/53 ; G06F21/55

Abstract:
Identifying malicious executables by analyzing proxy logs includes, at a server having connectivity to the Internet, retrieving sets of proxy logs from a plurality of proxy servers. Each proxy server of the plurality of proxy servers is associated with a network and generates network traffic logs for one or more nodes included in the network. Then, a set of executables hosted by each of the one or more nodes associated with each of the plurality of proxy servers is determined. Each set of executables is analyzed to detect a specific executable and portions of each of the network traffic logs that are associated with the specific executable are identified. An alert is generated indicating the portions of each of the network traffic logs as likely to be associated with the specific executable.
Public/Granted literature
- US20170230388A1 IDENTIFYING MALICIOUS EXECUTABLES BY ANALYZING PROXY LOGS Public/Granted day:2017-08-10
Information query