Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

83 results about "Botnet" patented technology

A botnet is a number of Internet-connected devices, each of which is running one or more bots. Botnets can be used to perform distributed denial-of-service attack (DDoS attack), steal data, send spam, and allows the attacker to access the device and its connection. The owner can control the botnet using command and control (C&C) software. The word "botnet" is a combination of the words "robot" and "network". The term is usually used with a negative or malicious connotation.

Detection of malicious domains

Disclosed are systems and methods that monitor for malicious and unauthorized behaviors, determine categories for detected malicious behaviors, determine why a domain is determined to be malicious, and provide information to users that identifies the categories and reasons as to why a domain is determined to be malicious. In some implementations, the disclosed systems and methods may be utilized to provide monitoring security to customers of a cloud service. For example, customers of a cloud service may maintain an account with the cloud service and the disclosed implementations may be utilized to protect those accounts from malicious attacks and cybercrimes such as, but not limited to, spam, phishing, malware, botnets, etc.
Owner:AMAZON TECH INC

Threat detection and mitigation in a virtualized computing environment

A service provider may deploy a security threat detection and mitigation platform in a multi-tenant virtualization environment that includes pluggable data collection, data analysis, and response components. The data analysis components may apply machine learning techniques to generate (based on training data sets) and refine (based on subsequently received data sets and feedback about the resulting classifications) predictors configured to detect particular types of security threats, such as denial of service attacks, botnets, scans, or remote desktop attacks. A data collection layer may collect, filter, organize, and curate network packet traffic data, network packet header data, or other information emitted by computing instances or applications executing on them, and provide the curated data as streams to the analysis layer. A response layer may automatically take action in response to threat detections (which may be overridden by an administrator) and may store classification data for subsequent analysis, feedback, and predictor refinement.
Owner:AMAZON TECH INC

System and method for midserver facilitation of mass scanning network traffic detection and analysis

A system and method that uses midservers located between an enterprise network and an external network to provide mass scanning network traffic detection and analysis capabilities for the enterprise network. The midserver may be loaded with configurations that allow it to operate as a mass scan event detector capable of detecting network sniffers, botnets, and malicious peer-to-peer connections which can lead to security vulnerabilities. In such configurations, midserver may receive and analyze network traffic to determine if the network traffic is suspicious based on heuristic and signature-based techniques, and then generate an appropriate response action which can be implemented to mitigate the risk.
Owner:QOMPLX INC

Botnet detection using transformer-based embeddings and similarity search

A method for classifying a digital certificate as malicious or non-malicious includes receiving the digital certificate from a network source and extracting textual fields from the certificate. The extracted text is embedded into a high-dimensional vector using a pretrained transformer-based encoder. The resulting test vector is queried against a vector data structure populated with reference vectors derived from known benign and malicious certificates. A similarity search is performed to identify a set of nearest reference vectors. A classification decision is made based on the labels of the most similar / nearest neighbors, using a voting mechanism. If a given set or number of them are labeled as malicious, the certificate is classified as malicious. If not, it is classified as benign. The classification result may trigger a network security action, such as blacklisting the associated IP address or identifying a botnet command and control server. The system may use various embedding techniques, including concatenating subject and issuer fields or embedding individual certificate attributes separately.
Owner:RAPID7 INC

Method for detecting maturity of greenhouse tomatoes based on improved YOLOv8n

The invention discloses a greenhouse tomato maturity detection method based on improved YOLOv8n, and relates to the technical field of target detection. Comprising the following steps: acquiring image data of tomatoes in a greenhouse within a preset time range, performing expansion preprocessing and enhanced expansion processing by using a SinGAN network to obtain processed tomato image data, and dividing the processed tomato image data into a training set and a test set; yOLOv8n is used as a backbone network, an SPD-Conv module is introduced into the front section of the backbone network, BoTNet and an attention mechanism are introduced into the tail end of the backbone network, a greenhouse tomato maturity detection model is constructed, and the trained greenhouse tomato maturity detection model is obtained through a training set and a test set; and inputting the processed tomato image data into the trained greenhouse tomato maturity detection model to obtain an indoor tomato maturity detection result.
Owner:NANJING UNIV OF FINANCE & ECONOMICS

Distributed denial of service attack detection method and device, equipment and storage medium

The invention relates to the technical field of network security, in particular to a method, a device and equipment for detecting a distributed denial of service (DDoS) attack and a storage medium, which are used for comprehensively detecting the DDoS attack so as to reduce the risk of the DDoS attack. The method comprises the steps that node information of a plurality of control nodes in an active state in a network is collected, each control node is used for controlling a botnet attacked by a distributed denial of service (DDoS), and the node information comprises address information and communication protocol information; for each control node, based on the node information of the control node, intercepting a communication instruction between the control node and a puppet host in the botnet, analyzing the communication instruction, obtaining corresponding attack task information, and obtaining host information of each puppet host controlled by the control node; and performing aggregation analysis on the node information of the plurality of control nodes, the corresponding attack task information and the host information of the associated puppet hosts to generate an attack detection result.
Owner:CHINA TELECOM NETWORK SECURITY TECH CO LTD

Botnet domain name determination method and device, and electronic equipment

The application discloses a botnet domain name determination method and device and electronic equipment. It relates to the technical field of data processing, the field of network security and other related technical fields. The method comprises the following steps: constructing a target network relationship graph according to target DNS data; performing community division on the target network relationship graph according to a community discovery algorithm to obtain multiple community structure information; and determining a target botnet domain name from the target DNS data according to the multiple community structure information. Through the application, the problem that the determination accuracy of the botnet domain name is relatively low in the related art, which is caused by calculating the similarity between the target domain name and the historical botnet domain name to determine whether the target domain name is a botnet domain name, is solved.
Owner:HILLSTONE NETWORKS CO LTD +1

Domain name resolution method and device based on domain name request risk management and control

ActiveCN115695373BReduce load pressureQuick screeningSecuring communicationDomain nameData set
The application discloses a domain name resolution method and device based on domain name request risk management and control, the method comprises the following steps: identifying domain name requests as normal domain name requests or abnormal domain name requests; according to the user domain name access behavior data set and the abnormal domain name association strength, evaluating the security rating and the security score of the user; sending the normal domain name requests initiated by users with different security ratings to the DNS server subset cluster corresponding to their levels, so that the DNS server subset cluster of the level responds to the normal domain name requests in order based on the security score; predicting the normal domain names with high probability of access to form a domain name resource list, which is used to cache the domain name resource list to the selected DNS server when the security rating of the user is higher than the set threshold, so as to improve the domain name resolution cache hit rate and the resolution efficiency. The application solves the problem of reduced performance of the domain name server caused by the low utilization rate of the conventional DNS server due to the zombie network attack.
Owner:INST OF SOFTWARE - CHINESE ACAD OF SCI

Device, method, and system for supporting botnet traffic detection

The invention relates to a method, a device (101), a system (106), a computer program (504) and a computer program product (505) for supporting botnet traffic detection. A device (101) for supporting botnet traffic detection obtains information associated with a first data flow of a first communication device (104a) and information associated with a second data flow of the first communication device (104a) or of a second communication device (104b), and trains a first and a second prediction model. The first and second prediction models are applied to data traffic and a label based on the outputs of the first and the second prediction models is associated with the traffic, wherein the label either indicates benign traffic or malicious traffic.
Owner:TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)

A DDoS defense system and method

The present invention belongs to the field of network security technology and specifically discloses a DDoS defense system and method, including: determining whether a client has a forged IP address; a server performing IP filtering on access requests from the client, classifying the client IP address into those with or without a history of access; and further determining whether the IP address is a trusted IP address, a whitelisted IP address, or a blacklisted IP address. The system then randomly retrieves a client from the trusted IP list in real time to determine whether communication between the client and the server is normal. The system can accurately detect DDoS attacks through multiple determinations and save the botnet IP addresses in an IP blacklist, effectively preventing further attacks from the same botnet.
Owner:XIAN MINGFU CLOUD COMPUTING CO LTD

Method and device for identifying C2 address, electronic equipment and storage medium

The invention provides a method and device for identifying a C2 address, electronic equipment and a storage medium, and relates to the technical field of security. According to the method, the C2 address is identified by analyzing the Botnet traffic, identifying the traffic of DNS and TCP protocol sessions and counting the traffic characteristics, so that the key characteristics of Botnet communication can be captured in time without depending on a preset rule, and the attack mode of a novel Botnet virus family can be quickly adapted. Compared with a traditional detection method based on IDS, the scheme effectively solves the problem that the defense capability is lagged due to attack changes, the real-time performance and accuracy of detection are greatly improved, network defense can respond to new threats more quickly, and the overall network security protection efficiency is enhanced.
Owner:QI AN XIN TECHNOLOGY GROUP INC

Analysis device, analysis method, and analysis program

Detect the C2 server that actually participated in the attack. In the analysis device, an identification unit identifies bots that perform a distributed denial-of-service attack from communication flow information. An extraction unit extracts servers with which a predetermined percentage or more of the identified bots have performed communication within a predetermined range of communication volume, based on past communications of the distributed denial-of-service attack.
Owner:NTT DOCOMO BUSINESS INC

Classification and identification method of underwater wavelength scale sound scattering object based on continuous wavelet transform and Botnet

The invention discloses an underwater wavelength scale sound scattering object classification and identification method based on continuous wavelet transform and Botnet, and the method comprises the steps: extracting the time-frequency joint features of a sound scattering signal through the continuous wavelet transform, and processing an obtained time-frequency graph through the feature extraction capability based on a convolutional neural network method, thereby recognizing and classifying an object. According to the method, a framework of ultrasonic scattering-time frequency analysis-deep learning is provided, the gradient disappearance problem in deep network training is effectively relieved through cross-layer jump connection, and it is ensured that the model can capture multi-level detailed information in a time frequency feature map; and global structure information of a time-frequency domain can be mined through a self-attention mechanism, so that the precision of a multi-category classification task is improved.
Owner:NANJING UNIV OF SCI & TECH

Botnet virus defense method, apparatus and device, and storage medium

The invention discloses a botnet virus defense method and device, equipment and a storage medium, and relates to the technical field of network security, and the method comprises the steps: collecting a target network data packet in network traffic through an edge firewall, and extracting the features of the target network data packet; determining a target attack detection model by using historical network traffic and a preset artificial intelligence technology through the AI center, performing lightweight processing on the target attack detection model to obtain a corresponding lightweight model, and issuing the lightweight model to the edge firewall; wherein the historical network traffic comprises botnet viruses; and detecting the botnet virus in the network flow on the edge firewall by using the lightweight model based on the characteristics of the target network data packet, and updating the rule of the edge firewall to defend the attack of the botnet virus. The Botnet virus defense effect can be improved through the edge firewall and the AI technology.
Owner:HANGZHOU DBAPPSECURITY CO LTD

System and method for passive identification and detection of botnets

A system and method for detecting botnets are provided. The method includes monitoring a network traffic to collect network data for a device; mapping the device to members of at least one stored botnet, wherein the mapping matches a network data of the device to network data of the members of the at least one stored botnet; determining the mapped device as a botnet device of an associated botnet upon matching the network data of the device to a network data of a member of the associated botnet, wherein the associated botnet is the at least one stored botnet; and logging the network data of the mapped device as being part of the at least one stored botnet.
Owner:RADWARE LTD

A method for analyzing network traffic to measure botnet control scale

This invention relates to a method for analyzing network traffic and measuring the control scale of a botnet. First, it collects samples of discovered botnet programs to establish a dataset of botnet command and control instruction characteristics. By analyzing inbound and outbound network traffic, it identifies and records session information matching the instruction characteristics, recording botnet command and control logs. It then correlates the command and control logs with domain name request logs in network traffic in real time, adding a C2 control domain name field to the command and control logs. Finally, it uses a botnet control scale measurement algorithm to analyze the command and control logs, calculating the cumulative number of communicating botnet IPs and the daily number of communicating botnet IPs for each botnet family, each C2 control domain name, and each C2 IP address, thereby detecting botnets with large or rapidly expanding control scales. This invention accurately identifies botnet traffic from network traffic accessing C2 servers and then calculates the botnet scale, providing more comprehensive coverage and accurate measurement.
Owner:NAT COMP NETWORK & INFORMATION SECURITY MANAGEMENT CENT

Detecting polymorphic botnets using an image recognition platform

Arrangements for detecting polymorphic botnets using a pattern matching engine are provided. The platform may train a pattern matching engine to generate image pattern statuses based on a training set of historical image patterns. The platform may automatically generate real-time interaction information based on monitoring interactions between user devices and cloud platforms. The platform may generate a potentially malicious image pattern based on the real-time interaction information. The platform may then input the image pattern into the pattern matching engine to generate an image pattern status for the image pattern. The platform may store the image pattern to a pattern storage repository. Based on identifying the image pattern as malicious, the platform may initiate a security action. The platform may update the pattern matching engine based on the image pattern and its image pattern status to detect future polymorphic botnet attacks.
Owner:BANK OF AMERICA CORP

Information processing device and botnet analysis method

To accurately identify a conning-tower server in a botnet and perform detailed analysis, such as classifying the botnet.SOLUTION: An information processing device 10 detects bots that constitute a botnet by analyzing packets observed on a dark net. Based on the packets transmitted from the detected bots, the information processing device 10 classifies the bots according to their types and identifies the common communication destination of the classified bots as a conning-tower server for the bots.SELECTED DRAWING: Figure 2
Owner:NIPPON TELEGRAPH & TELEPHONE CORP

Botnet traffic detection method and device and related equipment

The invention provides a botnet traffic detection method and device and related equipment, and relates to the technical field of networks. The method comprises the following steps: extracting meta-features of network encrypted traffic, the meta-features comprising request interval time, query type distribution and request packet-response packet size distribution; determining a target standard deviation of the request interval time, a first Shannon entropy of query type distribution and a compression ratio of a response packet; and determining whether the network encrypted traffic is botnet traffic based on the target standard deviation, the first Shannon entropy and the compression ratio. Through the technical means, the technical problem of low success rate of botnet detection in related technologies is solved.
Owner:CHINA TELECOM CORP LTD +1

An insulator fault detection method based on improved YOLOv5

The present invention relates to an insulator fault detection method based on improved YOLOv5, comprising the following steps: Step 1: Preprocess the insulator dataset and divide it into a training set, a validation set, and a test set according to a set ratio; Step 2: Combine MobileOne, BoTNet, and YOLOv5 to construct an MB-YOLOv5 model; Step 3: Input the training set and the validation set into the MB-YOLOv5 model for model training; Step 4: Perform structural reparameterization on the trained MB-YOLOv5 model; Step 5: Input the test set into the MB-YOLOv5 model after structural reparameterization to test the model performance; Step 6: Use the finally obtained MB-YOLOv5 model for insulator fault detection. This method is beneficial to improving the detection accuracy and detection speed.
Owner:FUZHOU UNIV

Botnet detection method and system

The application discloses a botnet detection method and system, and belongs to the technical field of network security. Firstly, current behavior data of each network node in a unit time length is collected. Then, the matching value of the behavior data between nodes is calculated to quantify the coordination degree of the nodes in three dimensions of time sequence synchronization, behavior similarity and communication graph structure. When multiple nodes have the same matching value, the nodes are determined as a network node group. Finally, the botnet node is confirmed by verifying the behavior consistency of the node group in continuous multiple historical periods. The botnet detection method provided by the application adopts multi-dimensional coordination analysis combined with a historical continuity verification mechanism, effectively overcomes the limitations of traditional single-node detection, significantly improves the detection accuracy and greatly reduces the false positive rate, and is suitable for real-time security protection in a large-scale network environment.
Owner:NANJING TECH UNIV

Method and system for underwater target sonar image detection region segmentation

The present application relates to the technical field of underwater sonar detection, and discloses a region segmentation method and system for underwater target sonar image detection, comprising an image acquisition module, an algorithm optimization module and a verification and evaluation module. The region segmentation method and system for underwater target sonar image detection are connected to a side scan sonar through the image acquisition module to collect sonar image data of all regions, then utilize image processing software to perform data enhancement on the sonar data set and construct an experimental data set, the algorithm optimization module sets the YOLOv9 algorithm model as a real-time target detection framework, then introduces a BoTNet network and a SimAm attention mechanism for optimization and improvement, and is used for extracting feature information in the experimental data set, has strong feature capturing capability, the verification and evaluation module calculates the average precision mean and score of each algorithm model according to the experimental data set, compares the detection precision of the improved YOLOv9 algorithm model with the YOLOv3 algorithm model, the YOLOv5 algorithm model, the YOLOv7 algorithm model and the YOLOv9 algorithm model, and has high wreck detection precision.
Owner:JIANGSU OCEAN UNIV +1

Water surface floating object detection method based on improved YOLOv9

The invention relates to a water surface floating object detection method based on improved YOLOv9, and belongs to the technical field of computer vision and target detection. The method comprises the steps that a feature extraction module based on a BiFormer dynamic sparse attention mechanism is introduced, and through double-layer routing attention and pyramid structure design, the retention capacity of shallow small target features is improved while the calculated amount is reduced; according to the method, a hybrid architecture fused with BoTNet is constructed, the BoTNet is embedded in a backbone network, and by means of collaborative optimization of a multi-head self-attention mechanism and depth separable convolution, the model can more accurately grasp features of targets of different scales; an anti-interference strategy guided by a CA attention mechanism is introduced, noise interference caused by water surface wave reflection is suppressed through space-channel double-branch cross-dimension interaction and a dynamic activation mechanism sensitive to coordinates, and the feature response intensity of a small target area is enhanced. According to the invention, the detection performance and complex environment adaptability of the model to small targets on the water surface can be significantly improved.
Owner:FUJIAN ZHONGRUI HANDING DIGITAL TECH CO LTD

A botnet traffic detection method based on deep reinforcement learning

The application designs a botnet traffic detection method based on deep reinforcement learning, constructs an intelligent OneR-DQN detection model based on the OneR classifier in machine learning and the deep Q network of deep reinforcement learning, and faces the existing botnet traffic dataset; first, the dataset is merged, data is preprocessed, and features that can be used for classification and training are reserved; second, the OneR classifier is used to test and judge each feature in the dataset one by one, and appropriate features are selected for training by the DQN model; finally, the experience pool mechanism unique to DQN is used to continuously extract independent experience and training samples for cross-training, thereby improving the accuracy of detection; the mixed dataset of the four CIC datasets CIC-IDS2017, CIC-DoS2017, CIC-IDS2018 and CIC-DDoS2019 is used to verify the detection model constructed by the application, and the result shows that the accuracy of the model constructed by the application is 99.08%, and the artificial intelligence automatic identification and judgment for botnet traffic are realized.
Owner:SHENYANG LIGONG UNIV

A method for automatic inventory and monitoring of botnet assets

PendingCN122316940APathPingNetwork behavior
This invention relates to the field of network behavior analysis technology, specifically a method for automatically inventorying and monitoring botnet assets. The method includes the following steps: extracting traffic and analyzing the five-tuple order to generate communication trajectories; identifying abnormal communication and time differences; dividing state sequences to analyze interruption relationships and determine botnet assets; and associating abnormal ports to update asset status. In this invention, by constructing continuous interaction trajectories around communication five-tuples combined with process and interface information, and introducing time intervals and adjacency relationships to characterize communication evolution paths, it integrates time interval sequence differences and position offset consistency to identify abnormal behavior characteristics, possessing stronger dynamic correlation capabilities. Through communication state sequence division and extraction of interruption intervals and attenuation relationships to characterize state evolution, and combining with associated communication records and trajectory existence for multi-dimensional correlation verification, it enables the identification of hidden control links and intermittent communication characteristics, improving the level of abnormal asset judgment and the stability of status updates.
Owner:CHENGDU JIWEI INTERNET OF THINGS GRP CO LTD

A bot host detection method, device, equipment and storage medium

This application discloses a method, apparatus, device, and storage medium for detecting botnet hosts. The method includes: acquiring NetFlow data of the network traffic of the host to be detected; extracting features from the NetFlow data to obtain target feature information; and using a KNN algorithm model to detect the target feature information to determine whether the host to be detected is a botnet host. This method improves detection efficiency by extracting target feature information consistent with botnet hosts based on NetFlow data. Furthermore, the use of the KNN algorithm model improves detection accuracy, enabling rapid identification of botnet hosts and timely blocking of malicious requests initiated by them, resulting in good timeliness.
Owner:CHINA MOBILEHANGZHOUINFORMATION TECH CO LTD +1

AGV three-dimensional obstacle detection method and system based on improved PointPill multi-modal fusion algorithm

The invention discloses an AGV (Automatic Guided Vehicle) three-dimensional obstacle detection method and system based on an improved PointPill multi-modal fusion algorithm, which introduces an ECA lightweight attention mechanism in a point cloud coding stage, enhances key geometric features, alleviates the insufficiency of sparse point cloud information, and reduces the calculation complexity and parameter quantity of the attention mechanism. A ConvNeXt V2 module is added in the point cloud backbone network, all feature channels are fully utilized, and the feature learning ability of the backbone network is improved. According to the method, the BotNet algorithm is used for carrying out feature extraction on the RGB image, in the deep convolution process, the global context modeling capacity is enhanced in a self-attention mode, the relation between the overall composition of the image and different object parts is better understood, and a more accurate classification decision is made. And finally, realizing bidirectional interaction between the point cloud features and the RGB image features by using a feature bidirectional fusion interactive fusion network, fully mining complementary information, realizing effective integration of two kinds of modal information, and improving obstacle detection precision.
Owner:JIANGSU UNIV

Iot botnet ddos attack defense method, device and storage medium

The application provides a kind of Internet of Things botnet DDoS attack defense method, device and storage medium, it is related to Internet of Things technical field, by the conversion relationship between sleeping device, normal device, latent device and attack device is constructed botnet DDoS attack attack-defense differential game model;Calculate attacker legal packet loss income, defender legal packet loss loss and attack cost and defense cost;According to the attacker legal packet loss income, defender legal packet loss loss and attack cost and defense cost, build instantaneous payment function;Solve the equilibrium solution of attack-defense zero-sum differential game model, obtain optimal saddle point strategy, analyze DDoS attack in Internet of Things botnet from the overall and dynamic point of view, to control the traffic that can be within the scope of victim processing to reach victim, while reducing the security loss of Internet of Things attack-defense system to a lower level.
Owner:BEIJING UNIV OF POSTS & TELECOMM

Network detection method and device based on internet of things equipment, equipment and storage medium

The application discloses a network detection method and device based on an Internet of Things equipment, equipment and a storage medium, and the method comprises the following steps: when a to-be-detected Internet of Things equipment accesses a network, acquiring periodic time statistical characteristics and general time statistical characteristics of the to-be-detected Internet of Things equipment; performing abnormality detection through an unsupervised abnormality detection model according to the periodic time statistical characteristics and the general time statistical characteristics, and obtaining a detection result; and determining whether the to-be-detected Internet of Things equipment is an abnormal Internet of Things equipment according to the detection result. Compared with the prior art, the application optimizes and expands the selection range of the characteristics by combining the periodic time statistical characteristics and the general time statistical characteristics to select the flow characteristics, and designs an improved clustering abnormality analysis algorithm based on a weighted distance, so that the identification accuracy of a botnet in the Internet of Things equipment is more comprehensively and reliably improved.
Owner:CHINA MOBILE GROUP DESIGN INST +1