Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

31 results about "Zombie" patented technology

In computing, a zombie is a computer connected to the Internet that has been compromised by a hacker, computer virus or trojan horse program and can be used to perform malicious tasks of one sort or another under remote direction. Botnets of zombie computers are often used to spread e-mail spam and launch denial-of-service attacks (DOS attacks). Most owners of "zombie" computers are unaware that their system is being used in this way. Because the owner tends to be unaware, these computers are metaphorically compared to fictional zombies. A coordinated DDoS attack by multiple botnet machines also resembles a "zombie horde attack", as depicted in fictional zombie films.

Implementing decoys in a network environment

A system includes one or more “BotMagnet” modules that are exposed to infection by malicious code. The BotMagnets may include one or more virtual machines hosting operating systems in which malicious code may be installed and executed without exposing sensitive data or other parts of a network. In particular, outbound traffic may be transmitted to a Sinkhole module that implements a service requested by the outbound traffic and transmits responses to the malicious code executing within the BotMagnet. Credentials for services implemented by a BotSink may be planted in an active directory (AD) server. The BotSink periodically uses the credentials thereby creating log entries indicating use thereof. When an attacker accesses the services using the credentials, the BotSink engages and monitors an attacker system and may generate an alert. Decoy services may be assigned to a domain and associated with names according to a naming convention of the domain.
Owner:SENTINELONE INC

Detection of malicious domains

Disclosed are systems and methods that monitor for malicious and unauthorized behaviors, determine categories for detected malicious behaviors, determine why a domain is determined to be malicious, and provide information to users that identifies the categories and reasons as to why a domain is determined to be malicious. In some implementations, the disclosed systems and methods may be utilized to provide monitoring security to customers of a cloud service. For example, customers of a cloud service may maintain an account with the cloud service and the disclosed implementations may be utilized to protect those accounts from malicious attacks and cybercrimes such as, but not limited to, spam, phishing, malware, botnets, etc.
Owner:AMAZON TECH INC

Botnet detection using transformer-based embeddings and similarity search

A method for classifying a digital certificate as malicious or non-malicious includes receiving the digital certificate from a network source and extracting textual fields from the certificate. The extracted text is embedded into a high-dimensional vector using a pretrained transformer-based encoder. The resulting test vector is queried against a vector data structure populated with reference vectors derived from known benign and malicious certificates. A similarity search is performed to identify a set of nearest reference vectors. A classification decision is made based on the labels of the most similar / nearest neighbors, using a voting mechanism. If a given set or number of them are labeled as malicious, the certificate is classified as malicious. If not, it is classified as benign. The classification result may trigger a network security action, such as blacklisting the associated IP address or identifying a botnet command and control server. The system may use various embedding techniques, including concatenating subject and issuer fields or embedding individual certificate attributes separately.
Owner:RAPID7 INC

Distributed denial of service attack detection method and device, equipment and storage medium

The invention relates to the technical field of network security, in particular to a method, a device and equipment for detecting a distributed denial of service (DDoS) attack and a storage medium, which are used for comprehensively detecting the DDoS attack so as to reduce the risk of the DDoS attack. The method comprises the steps that node information of a plurality of control nodes in an active state in a network is collected, each control node is used for controlling a botnet attacked by a distributed denial of service (DDoS), and the node information comprises address information and communication protocol information; for each control node, based on the node information of the control node, intercepting a communication instruction between the control node and a puppet host in the botnet, analyzing the communication instruction, obtaining corresponding attack task information, and obtaining host information of each puppet host controlled by the control node; and performing aggregation analysis on the node information of the plurality of control nodes, the corresponding attack task information and the host information of the associated puppet hosts to generate an attack detection result.
Owner:CHINA TELECOM NETWORK SECURITY TECH CO LTD

AI large model fused API asset intelligent management method and system

The invention discloses an AI large model fused API asset intelligent management method and system, and relates to the technical field of API data security management, and the API asset intelligent management mainly comprises the following steps: (1) carrying out multi-source API data collection and preprocessing; (2) on the basis of the preprocessed API data, extracting API features by fusing natural language processing and flow feature analysis, and generating an API comprehensive feature vector fusing API document features and flow features; and (3) identifying API assets based on the API comprehensive feature vector, firstly identifying normal API assets to form an enterprise API asset list, and then identifying shadow APIs and zombie APIs based on the enterprise API asset list. According to the scheme, the accuracy of API asset identification can be improved; meanwhile, a deep learning model and algorithm are adopted, features can be automatically learned and extracted, manual intervention is reduced, and efficiency is improved; moreover, according to the scheme of the invention, intelligent identification and anomaly detection of API assets can be realized, shadow APIs and zombie APIs can be found in time, and the security and stability of the system are guaranteed.
Owner:THE THIRD RES INST OF MIN OF PUBLIC SECURITY +1

A method, system, device and storage medium for handling wild pointers

Embodiments of the present application disclose a wild pointer processing method, system, device and storage medium. According to the type information of each memory object, the technical solution provided by the embodiments of the present application determines the memory object of a specified type as a target memory object; then in the case of releasing the target memory object, a target zombie object is created, the instruction set architecture pointer of the target memory object is modified, and the instruction set architecture pointer is pointed to the target zombie object; and then the target zombie object is saved to the application memory, so that when the calling party uses the instruction set architecture pointer to call the target memory object, the calling party is intercepted based on the target zombie object through a message forwarding mechanism, and the calling logic is processed. By using the above technical means, the wild pointer processing of the online running environment of the application program can be realized, the application program can be prevented from crashing, the running effect of the application program is optimized, and the user experience is improved.
Owner:BIGO TECH PTE LTD

Application putaway system and method of low-code platform

The invention provides an application putaway method and system for a low-code platform, a computer readable storage medium and a computer program product. The method comprises the steps that the low-code platform verifies a current user to determine whether the current user belongs to a pre-configured putaway permission group or not; if yes, responding to a trigger operation of the current user, and generating and sending an application putaway request to the security gateway by the low-code platform; sending the application putaway request to a unified authentication center for verification through the security gateway; if the verification is passed, forwarding the application shelving request to a target platform, and verifying the application shelving request by the target platform; and if the verification is passed, putting the application into the group corresponding to the belonging group information. Through the management of the shelving permission group of the low-code platform, only authorized users can be ensured to shelve applications, the permission handover during personnel change is simplified, and zombie applications are avoided. And meanwhile, the application can be simultaneously put on the computer end platform and the mobile end platform in a single request, so that the efficiency is improved.
Owner:CHINA RAILWAY CLOUD NETWORK INFORMATION TECH CO LTD

Method and device for identifying C2 address, electronic equipment and storage medium

The invention provides a method and device for identifying a C2 address, electronic equipment and a storage medium, and relates to the technical field of security. According to the method, the C2 address is identified by analyzing the Botnet traffic, identifying the traffic of DNS and TCP protocol sessions and counting the traffic characteristics, so that the key characteristics of Botnet communication can be captured in time without depending on a preset rule, and the attack mode of a novel Botnet virus family can be quickly adapted. Compared with a traditional detection method based on IDS, the scheme effectively solves the problem that the defense capability is lagged due to attack changes, the real-time performance and accuracy of detection are greatly improved, network defense can respond to new threats more quickly, and the overall network security protection efficiency is enhanced.
Owner:QI AN XIN TECHNOLOGY GROUP INC

Iot botnet ddos attack defense method, device and storage medium

The application provides a kind of Internet of Things botnet DDoS attack defense method, device and storage medium, it is related to Internet of Things technical field, by the conversion relationship between sleeping device, normal device, latent device and attack device is constructed botnet DDoS attack attack-defense differential game model;Calculate attacker legal packet loss income, defender legal packet loss loss and attack cost and defense cost;According to the attacker legal packet loss income, defender legal packet loss loss and attack cost and defense cost, build instantaneous payment function;Solve the equilibrium solution of attack-defense zero-sum differential game model, obtain optimal saddle point strategy, analyze DDoS attack in Internet of Things botnet from the overall and dynamic point of view, to control the traffic that can be within the scope of victim processing to reach victim, while reducing the security loss of Internet of Things attack-defense system to a lower level.
Owner:BEIJING UNIV OF POSTS & TELECOMM

DDoS attack real-time prediction method and system based on dynamic heterogeneous distillation network

The invention provides a DDoS attack real-time prediction method and system based on a dynamic heterogeneous distillation network, and the method comprises the steps: constructing a dynamic heterogeneous topological graph, carrying out the space-time convolution calculation and meta-knowledge distillation of the dynamic heterogeneous topological graph, obtaining a space-time distillation prediction network, and carrying out the multi-task driving to capture a network attack behavior; performing pulse frequency domain analysis on the network attack behavior, adding a Hamming window to the traffic data time sequence and executing fast Fourier transform to extract a frequency domain component, generating an adversarial sample and injecting disturbance, and detecting whether a low-frequency pulse attack exists in the network attack behavior; and blocking network attack behaviors in real time, performing incremental training on the space-time distillation network, and updating parameters of the space-time distillation network. According to the method, the defect of high omission ratio of a static mode can be overcome, so that zombie host migration has no place to hide, the bottleneck of real-time response of network attack behaviors is broken through, the robustness of a space-time distillation prediction network is improved, a prediction blind area is filled up, and a DDoS defense core pain point is solved.
Owner:XIAMEN ANSCEN NETWORK TECH CO LTD

Botnet management method and device based on deep protocol reverse analysis and storage medium

Embodiments of the present disclosure provide a botnet management method and device based on deep protocol reverse analysis, which comprises: deploying a plurality of high-interaction honeypots in a virtual machine or a container, simulating real operating systems, application services or Internet of Things devices to trap bot nodes; obtaining data packets between the bot nodes and the honeypots, reverse analyzing the communication protocols in the data packets to obtain protocol analysis results; based on the protocol analysis results, constructing a virtual C&C communication network to simulate the communication protocols of the attackers to send fake instructions to the connected bot nodes; recording the node information connected to the virtual C&C communication network, and constructing a node relationship graph based on the node information; and identifying abnormal behavior patterns based on the node relationship graph, triggering a defense mechanism or a countermeasure mechanism when an abnormal behavior is detected. The present scheme not only can discover and analyze bot nodes when encountering botnet attacks, but also can counterattack and attack the attackers through an active virtual command and control network.
Owner:NO 15 INST OF CHINA ELECTRONICS TECH GRP

Methods, systems, and apparatuses for query analysis and classification

Described herein are methods, systems, and apparatuses for query analysis and classification. A plurality of entity identifier queries associated with a plurality of entity identifiers may be received and classified as being legitimate or illegitimate. Illegitimate entity identifier queries may be associated with originating devices that are infected with malware. The originating devices may have sent the illegitimate entity identifier queries in an attempt to communicate with a command and control server(s) of a botnet. Such originating devices may be identified and one or more remedial actions may be performed.
Owner:COMCAST CABLE COMM LLC

A method for judging the authenticity of zombie Trojans on the Internet

The present invention discloses a method for determining the authenticity of zombie Trojans on the Internet, comprising the following steps: A: obtaining a zombie Trojan dataset to be determined and determining the zombie Trojan attribute factors of the zombie Trojan data to be determined; B: constructing a zombie Trojan information granularity model at a single granularity level; C: constructing a zombie Trojan information granularity model at multiple granularity levels; D: making a judgment based on the coordination of decision attributes and selecting the optimal zombie Trojan judgment granularity; E: selecting a zombie Trojan information granularity model at a corresponding level based on the optimal zombie Trojan judgment granularity, and then determining the authenticity of the corresponding zombie Trojan data to be determined by querying the log information of the host corresponding to the controlled terminal IP in the destination IP attribute function. The present invention can effectively improve the accuracy and efficiency of zombie Trojan judgment and more efficiently support the analysis of zombie Trojan events.
Owner:NAT COMPUTER NETWORK & INFORMATION SECURITY MANAGEMENT CENT HENAN BRANCH

MCP flooding attack detection method based on behavior characteristics

An MCP flooding attack detection method based on behavior characteristics comprises the following steps: collecting and learning a large amount of legal MCP traffic, extracting parameter length, request interval, nesting depth and response time characteristics, and constructing four-dimensional normal distribution as a legal traffic model based on the parameters, the request interval, the nesting depth and the response time characteristics; the probability density of the feature vector of each new request under the legal model is calculated to judge the abnormal request and the attack type thereof, finally, an SIR infectious disease dynamic model and an ARIMA time sequence model are further innovatively integrated to predict the zombie node scale and the attack trend, and the prediction result is used as input to automatically trigger and adjust a defense strategy; according to the method, botnet attack detection is carried out on the large language model integrated with the MCP protocol by utilizing the multi-dimensional behavior characteristics, so that attack detection and an adaptive defense strategy are effectively realized, and a security protection capability is also provided for a complex network environment in which the large language model is integrated with the MCP protocol; the invention further comprises a system, equipment and a storage medium for implementing the method.
Owner:XI'AN PETROLEUM UNIVERSITY

Stack-HAC for machine learning based botnet detection

Discussed herein are devices, systems, and methods for detecting anomalous or malicious processes based on a network session. A method includes receiving a network session, implementing a stacked hierarchical agglomerative clustering (HAC) algorithm that operates multiple HAC algorithms to identify respective clusters to which the network session maps, each HAC algorithm of the StackHAC algorithm operates using a different linkage function and distance pair, appending the respective clusters from the multiple HAC algorithms to a feature vector representing the network session resulting in an augmented feature space, and determining, using a classifier or clustering model that operates using the augmented feature space as input, whether each of the network sessions is associated with a network intrusion.
Owner:RAYTHEON CO

Mobile devices with zombie mode

This provides mobile devices that allow the use of NFC authentication functions (such as Apple Pay and Suica) even when the battery is completely dead. [Solution] The mobile device 1 includes a battery 10, an NFC chip 141, an SE chip 190, an NFC utilization processing unit 191, and a power generation unit 200 that converts vibration into electricity. Even when the battery 10 is completely depleted, if the user shakes the mobile device 1 immediately before using the NFC authentication function, the power from the power generation unit 200 will wake up the NFC chip 141. Subsequent power for short-range wireless communication and driving the SE chip 190, etc., is supplied by the power passively generated by the NFC chip 141 due to an external magnetic field. Therefore, the user can use the NFC authentication function even when the battery 10 and backup power are completely depleted.
Owner:HATSUMEIYA

Method, device and electronic equipment for determining a botnet master

PendingCN122339736AAttackEngineering
This disclosure provides a method for identifying the master controller of a botnet, relating to the field of network security technology, particularly attack attribution, botnets, and deep learning. The specific implementation scheme is as follows: In response to the detection of attack traffic targeting external communication addresses, a set of controlled hosts corresponding to the attack traffic is determined, and network flow data of each controlled host within a preset attack attribution time window is extracted; for any controlled host, botnet feature preprocessing is performed on the network flow data to generate host behavior description information; the host behavior description information of each controlled host is input into a large language model in the security field, and through the prompt information configured for botnet feature analysis in the large language model, a list of suspected master controllers corresponding to each controlled host is output; the lists of suspected master controllers of each controlled host are aggregated, attack correlation analysis is performed, and the target botnet master controller is determined based on the analysis results.
Owner:BEIJING BAIDU NETCOM SCI & TECH CO LTD

Classification-based suppression and blocking methods and systems for botnets with different communication architectures

The present invention provides a method and system for classifying and suppressing zombie networks facing different communication architectures, which relates to the field of network security technology. The method includes: determining an implementable suppression channel according to control instructions, heartbeat mechanisms, and data synchronization characteristics, in combination with the protocol characteristics and network structure to which they belong; matching a corresponding blocking scheme based on the suppression channel; the blocking scheme is selected according to the communication architecture type of the zombie network, and the communication architecture type includes centralized control C2 communication type, peer-to-peer P2P communication type, and hybrid type; implementing blocking measures matching the blocking scheme through policy scheduling, adjusting the suppression blocking intensity according to network feedback, coordinating multi-point linkage operations, and evaluating the blocking effect at the same time. The present invention enhances the ability to govern zombie networks in cyberspace by effectively cutting off and interfering with the communication links of centralized control communication type, peer-to-peer communication type, and hybrid type zombie networks.
Owner:CHINA INFORMATION TECH SECURITY EVALUATION CENT +1

A method and system for detecting process anomalies through process DNS behavior data

The present invention proposes a method and system for detecting process anomalies through process DNS behavior data. The method includes: S10, collecting process DNS logs; S20, matching and filtering the DNS log data based on preset rules to determine the DNS log data to be detected; S30, performing domain name splitting processing on the DNS log data to be detected based on a preset splitting strategy; S40, aggregating and grouping the split data, and de-duplicating and merging the registered domain name prefix data within each group to obtain a domain name transferable string; S50, performing anomaly detection on the domain name transferable string data within each group. The present invention does not rely on feature rules, but analyzes the DNS resolution behavior of the host process to accurately identify threats such as malicious bots and creeps in the host process using DGA to communicate with botnets and covert communication tunnels implemented by DNS. The innovative data aggregation and analysis method uses a low-complexity model to complete high-precision calculations.
Owner:CHINA ELECTRONICS CLOUD DIGITAL INTELLIGENCE TECH CO LTD

Botnet traffic detection method based on anti-convolution auto-encoder

The invention designs a botnet traffic detection method based on an adversarial convolution auto-encoder, which comprises the following steps of: firstly, cutting original network traffic into IP (Internet Protocol) with the same source and target, and then processing byte streams into a data form of 32 bytes multiplied by 32 bytes; secondly, a network model composed of a convolution encoder, a deconvolution decoder and a discriminator is constructed, the encoder is used for mapping input data to an implicit vector, and prior distribution is set as Gaussian distribution; in the training process, the quality of implicit vectors generated by an encoder is continuously optimized through confrontation of the encoder and a discriminator, finally, during testing, an initial threshold value is determined according to a mean value and a standard deviation of training data reconstruction loss, and a sliding window dynamic threshold value is introduced to adaptively adjust a classification boundary, so that the classification accuracy is improved. And detecting whether the input data belongs to normal flow or botnet flow by comparing the reconstruction loss obtained after the input data passes through the encoder and the decoder with the dynamic threshold value in the current sliding window.
Owner:NANJING UNIV OF POSTS & TELECOMM

Arcade Machine (Zombie Invaders)

1. The name of this design product: Amusement Machine (Zombie Invaders). 2. Purpose of this design product: for entertainment. 3. The key point of the design of this product lies in its shape. 4. The picture or photo that best illustrates the design points: three-dimensional picture.
Owner:ZHONGSHAN CHUANGJIA AMUSEMENT EQUIPMENT CO LTD

Method and system for managing concurrent requests of target application

The invention provides a method and system for managing concurrent requests of target applications, and the method comprises the steps: maintaining the concurrent request state of each target application in a distributed cache, including a maximum concurrent number limit value maxactiverequest and an active request set activerequest, and carrying out the concurrent check and access control when a new request is received. And the resources are automatically released when the request processing is completed or abnormal. The system further comprises a periodic cleaning module which is used for scanning and removing overtime requests and preventing zombie requests from occupying resources for a long time. The method further supports dynamic adjustment of concurrency limitation during operation, and adopts a streaming task encapsulation mechanism to simplify request processing logic. The technical scheme is suitable for an artificial intelligence model servitization deployment platform, and the stability of the system can be effectively improved.
Owner:JINAN INSPUR DATA TECH CO LTD

System

A system is provided.SOLUTION: A system comprising: an augmented reality device worn by a user; a sensor configured to detect a motion of the user; a display unit configured to receive data from a server and perform augmented reality display; a communication unit configured to communicate with the server and acquire an appearance position and timing of a zombie; and a determination unit configured to determine the motion of the user and display a reaction of the zombie based on a motion determination result.SELECTED DRAWING: Figure 1
Owner:SOFTBANK GROUP CORP

Methods, systems, and apparatuses for query analysis and classification

Described herein are methods, systems, and apparatuses for query analysis and classification. A plurality of entity identifier queries associated with a plurality of entity identifiers may be received and classified as being legitimate or illegitimate. Illegitimate entity identifier queries may be associated with originating devices that are infected with malware. The originating devices may have sent the illegitimate entity identifier queries in an attempt to communicate with a command and control server(s) of a botnet. Such originating devices may be identified and one or more remedial actions may be performed.
Owner:COMCAST CABLE COMM LLC

Botnet detection method, device, equipment, storage medium and program product

The application discloses a botnet detection method, device and equipment, a storage medium and a program product, relates to the technical field of network security, and discloses a botnet detection method, which comprises the following steps: acquiring a plurality of network alarm records of a target network group; constructing a first directed graph according to the plurality of network alarm records; calculating the attack similarity between the out-edge of a target node of any edge of the directed graph and the edge; retaining a target edge and nodes associated with the target edge in the first directed graph, wherein the attack similarity is greater than a preset attack similarity, obtaining a second directed graph; and calculating the botnet probability corresponding to each connected subgraph in the second directed graph, to obtain a botnet detection result. The application can improve the accuracy of botnet detection.
Owner:CHINA MOBILE INFORMATION TECHNOLOGY CO LTD +1

Botnet management method and device based on deep protocol reverse analysis

The embodiment of the invention provides a Botnet management method and device based on deep protocol reverse analysis. The method comprises the following steps: deploying a plurality of high-interaction honeypots in a virtual machine or a container, simulating a real operating system, application service or Internet of Things equipment, and trapping Botnet nodes; acquiring a data packet between the zombie node and the honeypot, and performing reverse analysis on a communication protocol in the data packet to obtain a protocol analysis result; constructing a virtual Camp based on a protocol analysis result; c, the communication network simulates a communication protocol of an attacker to send a forged instruction to the connected zombie node; the record is connected to the virtual Camp; c, communicating node information of the network, and constructing a node relation graph based on the node information; and identifying an abnormal behavior mode based on the node relation graph, and triggering a defense mechanism or a countering mechanism when an abnormal behavior is detected. According to the scheme, when the botnet attack is encountered, the botnet node can be found and analyzed, and an attacker can be countered and attacked through an active virtual command and a control network.
Owner:NO 15 INST OF CHINA ELECTRONICS TECH GRP

Botnet process resource recovery method and system, medium and product

The invention discloses a zombie process resource recovery method and system, a medium and a product, and the method comprises the steps: periodically carrying out process state inspection on continuous processes of an operating system, and adding process information of the continuous processes in a zombie state into a global zombie process chain table; selecting one piece of process information from the process information of the global zombie process chain table as current processing information, judging whether a corresponding target process meets a process recovery condition or not according to the information, and if the condition is met, directly executing resource recovery operation on the target process by a kernel; and processing the next piece of process information in the global zombie process chain table after the subsequent processing is completed, and if the condition is not met, continuing to process the next piece of process information in the global zombie process chain table. According to the method, the zombie process is directly recovered through the kernel, the business service interruption of the parent process is not caused, and the safe and effective recovery of the zombie process is realized.
Owner:KYLIN CORP

A simulation method for botnet propagation model analysis and target construction for IoT devices

A simulation method for analyzing botnet propagation models and constructing targets for IoT devices includes the following steps: constructing a network topology suitable for botnet virus propagation; identifying IoT devices with weak password vulnerabilities, obtaining and parsing the device firmware; using the acquired firmware information, using the QEMU emulator and system-level simulation technology to simulate the target firmware and target topology; and finally reproducing the botnet propagation and packaging it into a target. This method analyzes the Mirai propagation process to implement features such as malicious code anti-reboot and process immortality. Using the QEMU emulator to simulate the firmware, the constructed target scenario focuses on the customization of typical botnet virus simulations and propagation model analysis.
Owner:NANJING UNIV OF POSTS & TELECOMM

A method and system for managing concurrent requests of target applications

The present application provides a method and system for managing concurrent requests of target applications, wherein the method maintains the concurrent request status of each target application in a distributed cache, including the maximum concurrent limit value max_active_requests and the active request set active_requests, performs concurrency checks and access control when new requests are received, and automatically releases resources when the request processing is completed or an exception occurs. The system also includes a periodic cleanup module for scanning and removing timed-out requests to prevent zombie requests from occupying resources for a long time. The present invention further supports dynamic adjustment of concurrency limits at runtime, and adopts a streaming task encapsulation mechanism to simplify the request processing logic. This technical solution is suitable for artificial intelligence model service deployment platforms and can effectively improve the stability of the system.
Owner:JINAN INSPUR DATA TECH CO LTD