Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

66 results about "Botnet" patented technology

A botnet is a number of Internet-connected devices, each of which is running one or more bots. Botnets can be used to perform distributed denial-of-service attack (DDoS attack), steal data, send spam, and allows the attacker to access the device and its connection. The owner can control the botnet using command and control (C&C) software. The word "botnet" is a combination of the words "robot" and "network". The term is usually used with a negative or malicious connotation.

Detection of malicious domains

Disclosed are systems and methods that monitor for malicious and unauthorized behaviors, determine categories for detected malicious behaviors, determine why a domain is determined to be malicious, and provide information to users that identifies the categories and reasons as to why a domain is determined to be malicious. In some implementations, the disclosed systems and methods may be utilized to provide monitoring security to customers of a cloud service. For example, customers of a cloud service may maintain an account with the cloud service and the disclosed implementations may be utilized to protect those accounts from malicious attacks and cybercrimes such as, but not limited to, spam, phishing, malware, botnets, etc.
Owner:AMAZON TECH INC

Threat detection and mitigation in a virtualized computing environment

A service provider may deploy a security threat detection and mitigation platform in a multi-tenant virtualization environment that includes pluggable data collection, data analysis, and response components. The data analysis components may apply machine learning techniques to generate (based on training data sets) and refine (based on subsequently received data sets and feedback about the resulting classifications) predictors configured to detect particular types of security threats, such as denial of service attacks, botnets, scans, or remote desktop attacks. A data collection layer may collect, filter, organize, and curate network packet traffic data, network packet header data, or other information emitted by computing instances or applications executing on them, and provide the curated data as streams to the analysis layer. A response layer may automatically take action in response to threat detections (which may be overridden by an administrator) and may store classification data for subsequent analysis, feedback, and predictor refinement.
Owner:AMAZON TECH INC

Botnet detection using transformer-based embeddings and similarity search

A method for classifying a digital certificate as malicious or non-malicious includes receiving the digital certificate from a network source and extracting textual fields from the certificate. The extracted text is embedded into a high-dimensional vector using a pretrained transformer-based encoder. The resulting test vector is queried against a vector data structure populated with reference vectors derived from known benign and malicious certificates. A similarity search is performed to identify a set of nearest reference vectors. A classification decision is made based on the labels of the most similar / nearest neighbors, using a voting mechanism. If a given set or number of them are labeled as malicious, the certificate is classified as malicious. If not, it is classified as benign. The classification result may trigger a network security action, such as blacklisting the associated IP address or identifying a botnet command and control server. The system may use various embedding techniques, including concatenating subject and issuer fields or embedding individual certificate attributes separately.
Owner:RAPID7 INC

Botnet domain name determination method and device, and electronic equipment

The application discloses a botnet domain name determination method and device and electronic equipment. It relates to the technical field of data processing, the field of network security and other related technical fields. The method comprises the following steps: constructing a target network relationship graph according to target DNS data; performing community division on the target network relationship graph according to a community discovery algorithm to obtain multiple community structure information; and determining a target botnet domain name from the target DNS data according to the multiple community structure information. Through the application, the problem that the determination accuracy of the botnet domain name is relatively low in the related art, which is caused by calculating the similarity between the target domain name and the historical botnet domain name to determine whether the target domain name is a botnet domain name, is solved.
Owner:HILLSTONE NETWORKS CO LTD +1

Domain name resolution method and device based on domain name request risk management and control

ActiveCN115695373BReduce load pressureQuick screeningSecuring communicationDomain nameData set
The application discloses a domain name resolution method and device based on domain name request risk management and control, the method comprises the following steps: identifying domain name requests as normal domain name requests or abnormal domain name requests; according to the user domain name access behavior data set and the abnormal domain name association strength, evaluating the security rating and the security score of the user; sending the normal domain name requests initiated by users with different security ratings to the DNS server subset cluster corresponding to their levels, so that the DNS server subset cluster of the level responds to the normal domain name requests in order based on the security score; predicting the normal domain names with high probability of access to form a domain name resource list, which is used to cache the domain name resource list to the selected DNS server when the security rating of the user is higher than the set threshold, so as to improve the domain name resolution cache hit rate and the resolution efficiency. The application solves the problem of reduced performance of the domain name server caused by the low utilization rate of the conventional DNS server due to the zombie network attack.
Owner:INST OF SOFTWARE - CHINESE ACAD OF SCI

Device, method, and system for supporting botnet traffic detection

The invention relates to a method, a device (101), a system (106), a computer program (504) and a computer program product (505) for supporting botnet traffic detection. A device (101) for supporting botnet traffic detection obtains information associated with a first data flow of a first communication device (104a) and information associated with a second data flow of the first communication device (104a) or of a second communication device (104b), and trains a first and a second prediction model. The first and second prediction models are applied to data traffic and a label based on the outputs of the first and the second prediction models is associated with the traffic, wherein the label either indicates benign traffic or malicious traffic.
Owner:TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)

Method and device for identifying C2 address, electronic equipment and storage medium

The invention provides a method and device for identifying a C2 address, electronic equipment and a storage medium, and relates to the technical field of security. According to the method, the C2 address is identified by analyzing the Botnet traffic, identifying the traffic of DNS and TCP protocol sessions and counting the traffic characteristics, so that the key characteristics of Botnet communication can be captured in time without depending on a preset rule, and the attack mode of a novel Botnet virus family can be quickly adapted. Compared with a traditional detection method based on IDS, the scheme effectively solves the problem that the defense capability is lagged due to attack changes, the real-time performance and accuracy of detection are greatly improved, network defense can respond to new threats more quickly, and the overall network security protection efficiency is enhanced.
Owner:QI AN XIN TECHNOLOGY GROUP INC

Analysis device, analysis method, and analysis program

Detect the C2 server that actually participated in the attack. In the analysis device, an identification unit identifies bots that perform a distributed denial-of-service attack from communication flow information. An extraction unit extracts servers with which a predetermined percentage or more of the identified bots have performed communication within a predetermined range of communication volume, based on past communications of the distributed denial-of-service attack.
Owner:NTT DOCOMO BUSINESS INC

Classification and identification method of underwater wavelength scale sound scattering object based on continuous wavelet transform and Botnet

The invention discloses an underwater wavelength scale sound scattering object classification and identification method based on continuous wavelet transform and Botnet, and the method comprises the steps: extracting the time-frequency joint features of a sound scattering signal through the continuous wavelet transform, and processing an obtained time-frequency graph through the feature extraction capability based on a convolutional neural network method, thereby recognizing and classifying an object. According to the method, a framework of ultrasonic scattering-time frequency analysis-deep learning is provided, the gradient disappearance problem in deep network training is effectively relieved through cross-layer jump connection, and it is ensured that the model can capture multi-level detailed information in a time frequency feature map; and global structure information of a time-frequency domain can be mined through a self-attention mechanism, so that the precision of a multi-category classification task is improved.
Owner:NANJING UNIV OF SCI & TECH

Botnet virus defense method, apparatus and device, and storage medium

The invention discloses a botnet virus defense method and device, equipment and a storage medium, and relates to the technical field of network security, and the method comprises the steps: collecting a target network data packet in network traffic through an edge firewall, and extracting the features of the target network data packet; determining a target attack detection model by using historical network traffic and a preset artificial intelligence technology through the AI center, performing lightweight processing on the target attack detection model to obtain a corresponding lightweight model, and issuing the lightweight model to the edge firewall; wherein the historical network traffic comprises botnet viruses; and detecting the botnet virus in the network flow on the edge firewall by using the lightweight model based on the characteristics of the target network data packet, and updating the rule of the edge firewall to defend the attack of the botnet virus. The Botnet virus defense effect can be improved through the edge firewall and the AI technology.
Owner:HANGZHOU DBAPPSECURITY CO LTD

System and method for passive identification and detection of botnets

A system and method for detecting botnets are provided. The method includes monitoring a network traffic to collect network data for a device; mapping the device to members of at least one stored botnet, wherein the mapping matches a network data of the device to network data of the members of the at least one stored botnet; determining the mapped device as a botnet device of an associated botnet upon matching the network data of the device to a network data of a member of the associated botnet, wherein the associated botnet is the at least one stored botnet; and logging the network data of the mapped device as being part of the at least one stored botnet.
Owner:RADWARE LTD

A method for analyzing network traffic to measure botnet control scale

This invention relates to a method for analyzing network traffic and measuring the control scale of a botnet. First, it collects samples of discovered botnet programs to establish a dataset of botnet command and control instruction characteristics. By analyzing inbound and outbound network traffic, it identifies and records session information matching the instruction characteristics, recording botnet command and control logs. It then correlates the command and control logs with domain name request logs in network traffic in real time, adding a C2 control domain name field to the command and control logs. Finally, it uses a botnet control scale measurement algorithm to analyze the command and control logs, calculating the cumulative number of communicating botnet IPs and the daily number of communicating botnet IPs for each botnet family, each C2 control domain name, and each C2 IP address, thereby detecting botnets with large or rapidly expanding control scales. This invention accurately identifies botnet traffic from network traffic accessing C2 servers and then calculates the botnet scale, providing more comprehensive coverage and accurate measurement.
Owner:NAT COMP NETWORK & INFORMATION SECURITY MANAGEMENT CENT

Detecting polymorphic botnets using an image recognition platform

Arrangements for detecting polymorphic botnets using a pattern matching engine are provided. The platform may train a pattern matching engine to generate image pattern statuses based on a training set of historical image patterns. The platform may automatically generate real-time interaction information based on monitoring interactions between user devices and cloud platforms. The platform may generate a potentially malicious image pattern based on the real-time interaction information. The platform may then input the image pattern into the pattern matching engine to generate an image pattern status for the image pattern. The platform may store the image pattern to a pattern storage repository. Based on identifying the image pattern as malicious, the platform may initiate a security action. The platform may update the pattern matching engine based on the image pattern and its image pattern status to detect future polymorphic botnet attacks.
Owner:BANK OF AMERICA CORP

Information processing device and botnet analysis method

To accurately identify a conning-tower server in a botnet and perform detailed analysis, such as classifying the botnet.SOLUTION: An information processing device 10 detects bots that constitute a botnet by analyzing packets observed on a dark net. Based on the packets transmitted from the detected bots, the information processing device 10 classifies the bots according to their types and identifies the common communication destination of the classified bots as a conning-tower server for the bots.SELECTED DRAWING: Figure 2
Owner:NIPPON TELEGRAPH & TELEPHONE CORP

Botnet traffic detection method and device and related equipment

The invention provides a botnet traffic detection method and device and related equipment, and relates to the technical field of networks. The method comprises the following steps: extracting meta-features of network encrypted traffic, the meta-features comprising request interval time, query type distribution and request packet-response packet size distribution; determining a target standard deviation of the request interval time, a first Shannon entropy of query type distribution and a compression ratio of a response packet; and determining whether the network encrypted traffic is botnet traffic based on the target standard deviation, the first Shannon entropy and the compression ratio. Through the technical means, the technical problem of low success rate of botnet detection in related technologies is solved.
Owner:CHINA TELECOM CORP LTD +1

Botnet detection method and system

The application discloses a botnet detection method and system, and belongs to the technical field of network security. Firstly, current behavior data of each network node in a unit time length is collected. Then, the matching value of the behavior data between nodes is calculated to quantify the coordination degree of the nodes in three dimensions of time sequence synchronization, behavior similarity and communication graph structure. When multiple nodes have the same matching value, the nodes are determined as a network node group. Finally, the botnet node is confirmed by verifying the behavior consistency of the node group in continuous multiple historical periods. The botnet detection method provided by the application adopts multi-dimensional coordination analysis combined with a historical continuity verification mechanism, effectively overcomes the limitations of traditional single-node detection, significantly improves the detection accuracy and greatly reduces the false positive rate, and is suitable for real-time security protection in a large-scale network environment.
Owner:NANJING TECH UNIV

Method and system for underwater target sonar image detection region segmentation

The present application relates to the technical field of underwater sonar detection, and discloses a region segmentation method and system for underwater target sonar image detection, comprising an image acquisition module, an algorithm optimization module and a verification and evaluation module. The region segmentation method and system for underwater target sonar image detection are connected to a side scan sonar through the image acquisition module to collect sonar image data of all regions, then utilize image processing software to perform data enhancement on the sonar data set and construct an experimental data set, the algorithm optimization module sets the YOLOv9 algorithm model as a real-time target detection framework, then introduces a BoTNet network and a SimAm attention mechanism for optimization and improvement, and is used for extracting feature information in the experimental data set, has strong feature capturing capability, the verification and evaluation module calculates the average precision mean and score of each algorithm model according to the experimental data set, compares the detection precision of the improved YOLOv9 algorithm model with the YOLOv3 algorithm model, the YOLOv5 algorithm model, the YOLOv7 algorithm model and the YOLOv9 algorithm model, and has high wreck detection precision.
Owner:JIANGSU OCEAN UNIV +1

Water surface floating object detection method based on improved YOLOv9

The invention relates to a water surface floating object detection method based on improved YOLOv9, and belongs to the technical field of computer vision and target detection. The method comprises the steps that a feature extraction module based on a BiFormer dynamic sparse attention mechanism is introduced, and through double-layer routing attention and pyramid structure design, the retention capacity of shallow small target features is improved while the calculated amount is reduced; according to the method, a hybrid architecture fused with BoTNet is constructed, the BoTNet is embedded in a backbone network, and by means of collaborative optimization of a multi-head self-attention mechanism and depth separable convolution, the model can more accurately grasp features of targets of different scales; an anti-interference strategy guided by a CA attention mechanism is introduced, noise interference caused by water surface wave reflection is suppressed through space-channel double-branch cross-dimension interaction and a dynamic activation mechanism sensitive to coordinates, and the feature response intensity of a small target area is enhanced. According to the invention, the detection performance and complex environment adaptability of the model to small targets on the water surface can be significantly improved.
Owner:FUJIAN ZHONGRUI HANDING DIGITAL TECH CO LTD

A botnet traffic detection method based on deep reinforcement learning

The application designs a botnet traffic detection method based on deep reinforcement learning, constructs an intelligent OneR-DQN detection model based on the OneR classifier in machine learning and the deep Q network of deep reinforcement learning, and faces the existing botnet traffic dataset; first, the dataset is merged, data is preprocessed, and features that can be used for classification and training are reserved; second, the OneR classifier is used to test and judge each feature in the dataset one by one, and appropriate features are selected for training by the DQN model; finally, the experience pool mechanism unique to DQN is used to continuously extract independent experience and training samples for cross-training, thereby improving the accuracy of detection; the mixed dataset of the four CIC datasets CIC-IDS2017, CIC-DoS2017, CIC-IDS2018 and CIC-DDoS2019 is used to verify the detection model constructed by the application, and the result shows that the accuracy of the model constructed by the application is 99.08%, and the artificial intelligence automatic identification and judgment for botnet traffic are realized.
Owner:SHENYANG LIGONG UNIV

A method for automatic inventory and monitoring of botnet assets

PendingCN122316940APathPingNetwork behavior
This invention relates to the field of network behavior analysis technology, specifically a method for automatically inventorying and monitoring botnet assets. The method includes the following steps: extracting traffic and analyzing the five-tuple order to generate communication trajectories; identifying abnormal communication and time differences; dividing state sequences to analyze interruption relationships and determine botnet assets; and associating abnormal ports to update asset status. In this invention, by constructing continuous interaction trajectories around communication five-tuples combined with process and interface information, and introducing time intervals and adjacency relationships to characterize communication evolution paths, it integrates time interval sequence differences and position offset consistency to identify abnormal behavior characteristics, possessing stronger dynamic correlation capabilities. Through communication state sequence division and extraction of interruption intervals and attenuation relationships to characterize state evolution, and combining with associated communication records and trajectory existence for multi-dimensional correlation verification, it enables the identification of hidden control links and intermittent communication characteristics, improving the level of abnormal asset judgment and the stability of status updates.
Owner:CHENGDU JIWEI INTERNET OF THINGS GRP CO LTD

A bot host detection method, device, equipment and storage medium

This application discloses a method, apparatus, device, and storage medium for detecting botnet hosts. The method includes: acquiring NetFlow data of the network traffic of the host to be detected; extracting features from the NetFlow data to obtain target feature information; and using a KNN algorithm model to detect the target feature information to determine whether the host to be detected is a botnet host. This method improves detection efficiency by extracting target feature information consistent with botnet hosts based on NetFlow data. Furthermore, the use of the KNN algorithm model improves detection accuracy, enabling rapid identification of botnet hosts and timely blocking of malicious requests initiated by them, resulting in good timeliness.
Owner:CHINA MOBILEHANGZHOUINFORMATION TECH CO LTD +1

AGV three-dimensional obstacle detection method and system based on improved PointPill multi-modal fusion algorithm

The invention discloses an AGV (Automatic Guided Vehicle) three-dimensional obstacle detection method and system based on an improved PointPill multi-modal fusion algorithm, which introduces an ECA lightweight attention mechanism in a point cloud coding stage, enhances key geometric features, alleviates the insufficiency of sparse point cloud information, and reduces the calculation complexity and parameter quantity of the attention mechanism. A ConvNeXt V2 module is added in the point cloud backbone network, all feature channels are fully utilized, and the feature learning ability of the backbone network is improved. According to the method, the BotNet algorithm is used for carrying out feature extraction on the RGB image, in the deep convolution process, the global context modeling capacity is enhanced in a self-attention mode, the relation between the overall composition of the image and different object parts is better understood, and a more accurate classification decision is made. And finally, realizing bidirectional interaction between the point cloud features and the RGB image features by using a feature bidirectional fusion interactive fusion network, fully mining complementary information, realizing effective integration of two kinds of modal information, and improving obstacle detection precision.
Owner:JIANGSU UNIV

Iot botnet ddos attack defense method, device and storage medium

The application provides a kind of Internet of Things botnet DDoS attack defense method, device and storage medium, it is related to Internet of Things technical field, by the conversion relationship between sleeping device, normal device, latent device and attack device is constructed botnet DDoS attack attack-defense differential game model;Calculate attacker legal packet loss income, defender legal packet loss loss and attack cost and defense cost;According to the attacker legal packet loss income, defender legal packet loss loss and attack cost and defense cost, build instantaneous payment function;Solve the equilibrium solution of attack-defense zero-sum differential game model, obtain optimal saddle point strategy, analyze DDoS attack in Internet of Things botnet from the overall and dynamic point of view, to control the traffic that can be within the scope of victim processing to reach victim, while reducing the security loss of Internet of Things attack-defense system to a lower level.
Owner:BEIJING UNIV OF POSTS & TELECOMM

Network detection method and device based on internet of things equipment, equipment and storage medium

The application discloses a network detection method and device based on an Internet of Things equipment, equipment and a storage medium, and the method comprises the following steps: when a to-be-detected Internet of Things equipment accesses a network, acquiring periodic time statistical characteristics and general time statistical characteristics of the to-be-detected Internet of Things equipment; performing abnormality detection through an unsupervised abnormality detection model according to the periodic time statistical characteristics and the general time statistical characteristics, and obtaining a detection result; and determining whether the to-be-detected Internet of Things equipment is an abnormal Internet of Things equipment according to the detection result. Compared with the prior art, the application optimizes and expands the selection range of the characteristics by combining the periodic time statistical characteristics and the general time statistical characteristics to select the flow characteristics, and designs an improved clustering abnormality analysis algorithm based on a weighted distance, so that the identification accuracy of a botnet in the Internet of Things equipment is more comprehensively and reliably improved.
Owner:CHINA MOBILE GROUP DESIGN INST +1

Mining belt conveyor belt longitudinal tearing detection method based on improved YOLOv5 network

The invention discloses a mining belt conveyor belt longitudinal tearing detection method based on an improved YOLOv5 network. The mining belt conveyor belt longitudinal tearing detection method comprises the following steps that data are collected on site in a mine field; making a conveyor belt tearing data set; preprocessing the data; a YOLOv5 network is configured; a BoTNet attention mechanism is added; the ShapeIOU is used for calculating the loss; model training and parameter adjustment; evaluating and testing the performance of the model; and comparing algorithms. According to the mining belt conveyor belt longitudinal tear detection method based on the improved YOLOv5 network, tear damage to the surface of a conveyor belt can be rapidly and accurately recognized, particularly, good detection precision is achieved for small tear, the false detection rate and the omission ratio of manual detection are reduced, and the detection efficiency is improved. And the tearing detection precision and speed of the conveyor are greatly improved. Moreover, the invention designs a novel conveyor tearing detection algorithm, and the detection precision of the model on a tiny target is remarkably improved. According to the invention, non-stop real-time detection can be realized, and the problem of manual detection efficiency of enterprises is solved.
Owner:XINJIANG UNIVERSITY

A method and system for detecting the life cycle of an internet of things botnet based on a reverse detection honeypot

The application relates to a method and system for detecting the life cycle of an Internet of Things (IoT) botnet based on a reverse detection honeypot, and belongs to the technical field of network security detection and defense. The application aims to accurately identify the life cycle of IoT botnet traffic captured by a reverse detection honeypot, and to avoid the virtual detection technology of attackers to achieve higher deception of IoT botnet traffic. First, a honeypot with a reverse detection function is designed based on a generative adversarial network, and after training, realistic response data is generated according to different request data, so that the deception ability of the honeypot is improved. An IoT botnet life cycle detection method is designed based on a fusion long short-term memory network. After training of the Fusion-LSTM, the life cycle of IoT botnet traffic captured by the reverse detection honeypot can be accurately identified. The method can avoid the virtual detection technology of attackers to achieve higher deception of IoT botnet traffic, and can accurately identify the life cycle of the traffic, so that protection and response can be made as early as possible.
Owner:HARBIN INST OF TECH

Botnet detection method based on multi-modal stacked autoencoder

ActiveCN117640190BData setEngineering
The application discloses a botnet detection method based on a multi-modal stacked autoencoder. The method comprises the following steps: obtaining an executable file of an application; performing dynamic analysis and static analysis on a dataset containing benign programs and bot programs respectively, and extracting flow-based dynamic features and printable string information graph-based static features; pre-training two stacked autoencoders to encode flow-based features and graph-based features respectively, and extract deep features; fusing the dynamic features and the static features based on a multi-modal autoencoder; fine-tuning the multi-modal stacked autoencoder model; taking the encoder of the trained multi-modal stacked autoencoder model as a feature extractor, taking the output of a shared hidden layer as the input of a softmax layer, and performing bot program detection. The application can automatically fuse static features and dynamic features through an improved multi-modal stacked autoencoder, can learn the complex relationship between two different modal features, can fully play the advantages of a hybrid analysis method, and can improve the precision of detecting botnet programs.
Owner:HOHAI UNIV

Small target detection method and system based on aerial photography of improved YOLOv5 unmanned aerial vehicle

The invention relates to the technical field of target detection, and particularly provides an improved YOLOv5 unmanned aerial vehicle aerial photography small target detection method and device, a CSPDarkNet backbone network of YOLOv5s is replaced by BoTNet, a global context dependency relationship is modeled through a Transform module, and the semantic information capture capability of a small target is enhanced. Compared with the prior art, loss caused by emergencies can be reduced to the maximum extent, an innovative technical scheme is provided for monitoring, early warning and emergency disposal, and wide application prospects are shown in the field of public safety.
Owner:浪潮智慧城市科技有限公司

Internet of Things botnet detection method and system fusing multi-dimensional information

The invention relates to the field of network detection, and particularly discloses an Internet of Things botnet detection method and system fused with multi-dimensional information, which converts original flow data into a structured network flow record through flow feature aggregation, and lays a foundation for deep analysis. Secondly, the flow records with the timestamps are constructed into a time sequence dynamic communication graph, and therefore isolated network events are converted into a network topology structure capable of reflecting the interaction relation between devices and behavior evolution; and finally, introducing a time graph attention mechanism, and carrying out aggregation learning of time sequence perception on nodes and neighborhood information thereof in the dynamic graph. The mechanism can adaptively focus on key cooperative communication behaviors, deeply fuse multi-dimensional information such as topological structures, interaction contents and time evolution of nodes, and generate feature representation with high discrimination, so that a hidden and cooperative attack mode of the botnet is effectively identified, and the accuracy and robustness of detection are improved.
Owner:ZHONGYUAN ENGINEERING COLLEGE