Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

22 results about "Zombie" patented technology

In computing, a zombie is a computer connected to the Internet that has been compromised by a hacker, computer virus or trojan horse program and can be used to perform malicious tasks of one sort or another under remote direction. Botnets of zombie computers are often used to spread e-mail spam and launch denial-of-service attacks (DOS attacks). Most owners of "zombie" computers are unaware that their system is being used in this way. Because the owner tends to be unaware, these computers are metaphorically compared to fictional zombies. A coordinated DDoS attack by multiple botnet machines also resembles a "zombie horde attack", as depicted in fictional zombie films.

Botnet detection using transformer-based embeddings and similarity search

A method for classifying a digital certificate as malicious or non-malicious includes receiving the digital certificate from a network source and extracting textual fields from the certificate. The extracted text is embedded into a high-dimensional vector using a pretrained transformer-based encoder. The resulting test vector is queried against a vector data structure populated with reference vectors derived from known benign and malicious certificates. A similarity search is performed to identify a set of nearest reference vectors. A classification decision is made based on the labels of the most similar / nearest neighbors, using a voting mechanism. If a given set or number of them are labeled as malicious, the certificate is classified as malicious. If not, it is classified as benign. The classification result may trigger a network security action, such as blacklisting the associated IP address or identifying a botnet command and control server. The system may use various embedding techniques, including concatenating subject and issuer fields or embedding individual certificate attributes separately.
Owner:RAPID7 INC

AI large model fused API asset intelligent management method and system

The invention discloses an AI large model fused API asset intelligent management method and system, and relates to the technical field of API data security management, and the API asset intelligent management mainly comprises the following steps: (1) carrying out multi-source API data collection and preprocessing; (2) on the basis of the preprocessed API data, extracting API features by fusing natural language processing and flow feature analysis, and generating an API comprehensive feature vector fusing API document features and flow features; and (3) identifying API assets based on the API comprehensive feature vector, firstly identifying normal API assets to form an enterprise API asset list, and then identifying shadow APIs and zombie APIs based on the enterprise API asset list. According to the scheme, the accuracy of API asset identification can be improved; meanwhile, a deep learning model and algorithm are adopted, features can be automatically learned and extracted, manual intervention is reduced, and efficiency is improved; moreover, according to the scheme of the invention, intelligent identification and anomaly detection of API assets can be realized, shadow APIs and zombie APIs can be found in time, and the security and stability of the system are guaranteed.
Owner:THE THIRD RES INST OF MIN OF PUBLIC SECURITY +1

A method, system, device and storage medium for handling wild pointers

Embodiments of the present application disclose a wild pointer processing method, system, device and storage medium. According to the type information of each memory object, the technical solution provided by the embodiments of the present application determines the memory object of a specified type as a target memory object; then in the case of releasing the target memory object, a target zombie object is created, the instruction set architecture pointer of the target memory object is modified, and the instruction set architecture pointer is pointed to the target zombie object; and then the target zombie object is saved to the application memory, so that when the calling party uses the instruction set architecture pointer to call the target memory object, the calling party is intercepted based on the target zombie object through a message forwarding mechanism, and the calling logic is processed. By using the above technical means, the wild pointer processing of the online running environment of the application program can be realized, the application program can be prevented from crashing, the running effect of the application program is optimized, and the user experience is improved.
Owner:BIGO TECH PTE LTD

Application putaway system and method of low-code platform

The invention provides an application putaway method and system for a low-code platform, a computer readable storage medium and a computer program product. The method comprises the steps that the low-code platform verifies a current user to determine whether the current user belongs to a pre-configured putaway permission group or not; if yes, responding to a trigger operation of the current user, and generating and sending an application putaway request to the security gateway by the low-code platform; sending the application putaway request to a unified authentication center for verification through the security gateway; if the verification is passed, forwarding the application shelving request to a target platform, and verifying the application shelving request by the target platform; and if the verification is passed, putting the application into the group corresponding to the belonging group information. Through the management of the shelving permission group of the low-code platform, only authorized users can be ensured to shelve applications, the permission handover during personnel change is simplified, and zombie applications are avoided. And meanwhile, the application can be simultaneously put on the computer end platform and the mobile end platform in a single request, so that the efficiency is improved.
Owner:CHINA RAILWAY CLOUD NETWORK INFORMATION TECH CO LTD

Method and device for identifying C2 address, electronic equipment and storage medium

The invention provides a method and device for identifying a C2 address, electronic equipment and a storage medium, and relates to the technical field of security. According to the method, the C2 address is identified by analyzing the Botnet traffic, identifying the traffic of DNS and TCP protocol sessions and counting the traffic characteristics, so that the key characteristics of Botnet communication can be captured in time without depending on a preset rule, and the attack mode of a novel Botnet virus family can be quickly adapted. Compared with a traditional detection method based on IDS, the scheme effectively solves the problem that the defense capability is lagged due to attack changes, the real-time performance and accuracy of detection are greatly improved, network defense can respond to new threats more quickly, and the overall network security protection efficiency is enhanced.
Owner:QI AN XIN TECHNOLOGY GROUP INC

Iot botnet ddos attack defense method, device and storage medium

The application provides a kind of Internet of Things botnet DDoS attack defense method, device and storage medium, it is related to Internet of Things technical field, by the conversion relationship between sleeping device, normal device, latent device and attack device is constructed botnet DDoS attack attack-defense differential game model;Calculate attacker legal packet loss income, defender legal packet loss loss and attack cost and defense cost;According to the attacker legal packet loss income, defender legal packet loss loss and attack cost and defense cost, build instantaneous payment function;Solve the equilibrium solution of attack-defense zero-sum differential game model, obtain optimal saddle point strategy, analyze DDoS attack in Internet of Things botnet from the overall and dynamic point of view, to control the traffic that can be within the scope of victim processing to reach victim, while reducing the security loss of Internet of Things attack-defense system to a lower level.
Owner:BEIJING UNIV OF POSTS & TELECOMM

DDoS attack real-time prediction method and system based on dynamic heterogeneous distillation network

The invention provides a DDoS attack real-time prediction method and system based on a dynamic heterogeneous distillation network, and the method comprises the steps: constructing a dynamic heterogeneous topological graph, carrying out the space-time convolution calculation and meta-knowledge distillation of the dynamic heterogeneous topological graph, obtaining a space-time distillation prediction network, and carrying out the multi-task driving to capture a network attack behavior; performing pulse frequency domain analysis on the network attack behavior, adding a Hamming window to the traffic data time sequence and executing fast Fourier transform to extract a frequency domain component, generating an adversarial sample and injecting disturbance, and detecting whether a low-frequency pulse attack exists in the network attack behavior; and blocking network attack behaviors in real time, performing incremental training on the space-time distillation network, and updating parameters of the space-time distillation network. According to the method, the defect of high omission ratio of a static mode can be overcome, so that zombie host migration has no place to hide, the bottleneck of real-time response of network attack behaviors is broken through, the robustness of a space-time distillation prediction network is improved, a prediction blind area is filled up, and a DDoS defense core pain point is solved.
Owner:XIAMEN ANSCEN NETWORK TECH CO LTD

Botnet management method and device based on deep protocol reverse analysis and storage medium

Embodiments of the present disclosure provide a botnet management method and device based on deep protocol reverse analysis, which comprises: deploying a plurality of high-interaction honeypots in a virtual machine or a container, simulating real operating systems, application services or Internet of Things devices to trap bot nodes; obtaining data packets between the bot nodes and the honeypots, reverse analyzing the communication protocols in the data packets to obtain protocol analysis results; based on the protocol analysis results, constructing a virtual C&C communication network to simulate the communication protocols of the attackers to send fake instructions to the connected bot nodes; recording the node information connected to the virtual C&C communication network, and constructing a node relationship graph based on the node information; and identifying abnormal behavior patterns based on the node relationship graph, triggering a defense mechanism or a countermeasure mechanism when an abnormal behavior is detected. The present scheme not only can discover and analyze bot nodes when encountering botnet attacks, but also can counterattack and attack the attackers through an active virtual command and control network.
Owner:NO 15 INST OF CHINA ELECTRONICS TECH GRP

Methods, systems, and apparatuses for query analysis and classification

Described herein are methods, systems, and apparatuses for query analysis and classification. A plurality of entity identifier queries associated with a plurality of entity identifiers may be received and classified as being legitimate or illegitimate. Illegitimate entity identifier queries may be associated with originating devices that are infected with malware. The originating devices may have sent the illegitimate entity identifier queries in an attempt to communicate with a command and control server(s) of a botnet. Such originating devices may be identified and one or more remedial actions may be performed.
Owner:COMCAST CABLE COMM LLC

A method for judging the authenticity of zombie Trojans on the Internet

The present invention discloses a method for determining the authenticity of zombie Trojans on the Internet, comprising the following steps: A: obtaining a zombie Trojan dataset to be determined and determining the zombie Trojan attribute factors of the zombie Trojan data to be determined; B: constructing a zombie Trojan information granularity model at a single granularity level; C: constructing a zombie Trojan information granularity model at multiple granularity levels; D: making a judgment based on the coordination of decision attributes and selecting the optimal zombie Trojan judgment granularity; E: selecting a zombie Trojan information granularity model at a corresponding level based on the optimal zombie Trojan judgment granularity, and then determining the authenticity of the corresponding zombie Trojan data to be determined by querying the log information of the host corresponding to the controlled terminal IP in the destination IP attribute function. The present invention can effectively improve the accuracy and efficiency of zombie Trojan judgment and more efficiently support the analysis of zombie Trojan events.
Owner:NAT COMPUTER NETWORK & INFORMATION SECURITY MANAGEMENT CENT HENAN BRANCH

MCP flooding attack detection method based on behavior characteristics

An MCP flooding attack detection method based on behavior characteristics comprises the following steps: collecting and learning a large amount of legal MCP traffic, extracting parameter length, request interval, nesting depth and response time characteristics, and constructing four-dimensional normal distribution as a legal traffic model based on the parameters, the request interval, the nesting depth and the response time characteristics; the probability density of the feature vector of each new request under the legal model is calculated to judge the abnormal request and the attack type thereof, finally, an SIR infectious disease dynamic model and an ARIMA time sequence model are further innovatively integrated to predict the zombie node scale and the attack trend, and the prediction result is used as input to automatically trigger and adjust a defense strategy; according to the method, botnet attack detection is carried out on the large language model integrated with the MCP protocol by utilizing the multi-dimensional behavior characteristics, so that attack detection and an adaptive defense strategy are effectively realized, and a security protection capability is also provided for a complex network environment in which the large language model is integrated with the MCP protocol; the invention further comprises a system, equipment and a storage medium for implementing the method.
Owner:XI'AN PETROLEUM UNIVERSITY

Mobile devices with zombie mode

This provides mobile devices that allow the use of NFC authentication functions (such as Apple Pay and Suica) even when the battery is completely dead. [Solution] The mobile device 1 includes a battery 10, an NFC chip 141, an SE chip 190, an NFC utilization processing unit 191, and a power generation unit 200 that converts vibration into electricity. Even when the battery 10 is completely depleted, if the user shakes the mobile device 1 immediately before using the NFC authentication function, the power from the power generation unit 200 will wake up the NFC chip 141. Subsequent power for short-range wireless communication and driving the SE chip 190, etc., is supplied by the power passively generated by the NFC chip 141 due to an external magnetic field. Therefore, the user can use the NFC authentication function even when the battery 10 and backup power are completely depleted.
Owner:HATSUMEIYA

Method, device and electronic equipment for determining a botnet master

PendingCN122339736AAttackEngineering
This disclosure provides a method for identifying the master controller of a botnet, relating to the field of network security technology, particularly attack attribution, botnets, and deep learning. The specific implementation scheme is as follows: In response to the detection of attack traffic targeting external communication addresses, a set of controlled hosts corresponding to the attack traffic is determined, and network flow data of each controlled host within a preset attack attribution time window is extracted; for any controlled host, botnet feature preprocessing is performed on the network flow data to generate host behavior description information; the host behavior description information of each controlled host is input into a large language model in the security field, and through the prompt information configured for botnet feature analysis in the large language model, a list of suspected master controllers corresponding to each controlled host is output; the lists of suspected master controllers of each controlled host are aggregated, attack correlation analysis is performed, and the target botnet master controller is determined based on the analysis results.
Owner:BEIJING BAIDU NETCOM SCI & TECH CO LTD

Classification-based suppression and blocking methods and systems for botnets with different communication architectures

The present invention provides a method and system for classifying and suppressing zombie networks facing different communication architectures, which relates to the field of network security technology. The method includes: determining an implementable suppression channel according to control instructions, heartbeat mechanisms, and data synchronization characteristics, in combination with the protocol characteristics and network structure to which they belong; matching a corresponding blocking scheme based on the suppression channel; the blocking scheme is selected according to the communication architecture type of the zombie network, and the communication architecture type includes centralized control C2 communication type, peer-to-peer P2P communication type, and hybrid type; implementing blocking measures matching the blocking scheme through policy scheduling, adjusting the suppression blocking intensity according to network feedback, coordinating multi-point linkage operations, and evaluating the blocking effect at the same time. The present invention enhances the ability to govern zombie networks in cyberspace by effectively cutting off and interfering with the communication links of centralized control communication type, peer-to-peer communication type, and hybrid type zombie networks.
Owner:CHINA INFORMATION TECH SECURITY EVALUATION CENT +1

A method and system for detecting process anomalies through process DNS behavior data

The present invention proposes a method and system for detecting process anomalies through process DNS behavior data. The method includes: S10, collecting process DNS logs; S20, matching and filtering the DNS log data based on preset rules to determine the DNS log data to be detected; S30, performing domain name splitting processing on the DNS log data to be detected based on a preset splitting strategy; S40, aggregating and grouping the split data, and de-duplicating and merging the registered domain name prefix data within each group to obtain a domain name transferable string; S50, performing anomaly detection on the domain name transferable string data within each group. The present invention does not rely on feature rules, but analyzes the DNS resolution behavior of the host process to accurately identify threats such as malicious bots and creeps in the host process using DGA to communicate with botnets and covert communication tunnels implemented by DNS. The innovative data aggregation and analysis method uses a low-complexity model to complete high-precision calculations.
Owner:CHINA ELECTRONICS CLOUD DIGITAL INTELLIGENCE TECH CO LTD

System

A system is provided.SOLUTION: A system comprising: an augmented reality device worn by a user; a sensor configured to detect a motion of the user; a display unit configured to receive data from a server and perform augmented reality display; a communication unit configured to communicate with the server and acquire an appearance position and timing of a zombie; and a determination unit configured to determine the motion of the user and display a reaction of the zombie based on a motion determination result.SELECTED DRAWING: Figure 1
Owner:SOFTBANK GROUP CORP

Methods, systems, and apparatuses for query analysis and classification

Described herein are methods, systems, and apparatuses for query analysis and classification. A plurality of entity identifier queries associated with a plurality of entity identifiers may be received and classified as being legitimate or illegitimate. Illegitimate entity identifier queries may be associated with originating devices that are infected with malware. The originating devices may have sent the illegitimate entity identifier queries in an attempt to communicate with a command and control server(s) of a botnet. Such originating devices may be identified and one or more remedial actions may be performed.
Owner:COMCAST CABLE COMM LLC

Botnet detection method, device, equipment, storage medium and program product

The application discloses a botnet detection method, device and equipment, a storage medium and a program product, relates to the technical field of network security, and discloses a botnet detection method, which comprises the following steps: acquiring a plurality of network alarm records of a target network group; constructing a first directed graph according to the plurality of network alarm records; calculating the attack similarity between the out-edge of a target node of any edge of the directed graph and the edge; retaining a target edge and nodes associated with the target edge in the first directed graph, wherein the attack similarity is greater than a preset attack similarity, obtaining a second directed graph; and calculating the botnet probability corresponding to each connected subgraph in the second directed graph, to obtain a botnet detection result. The application can improve the accuracy of botnet detection.
Owner:CHINA MOBILE INFORMATION TECHNOLOGY CO LTD +1

Botnet management method and device based on deep protocol reverse analysis

The embodiment of the invention provides a Botnet management method and device based on deep protocol reverse analysis. The method comprises the following steps: deploying a plurality of high-interaction honeypots in a virtual machine or a container, simulating a real operating system, application service or Internet of Things equipment, and trapping Botnet nodes; acquiring a data packet between the zombie node and the honeypot, and performing reverse analysis on a communication protocol in the data packet to obtain a protocol analysis result; constructing a virtual Camp based on a protocol analysis result; c, the communication network simulates a communication protocol of an attacker to send a forged instruction to the connected zombie node; the record is connected to the virtual Camp; c, communicating node information of the network, and constructing a node relation graph based on the node information; and identifying an abnormal behavior mode based on the node relation graph, and triggering a defense mechanism or a countering mechanism when an abnormal behavior is detected. According to the scheme, when the botnet attack is encountered, the botnet node can be found and analyzed, and an attacker can be countered and attacked through an active virtual command and a control network.
Owner:NO 15 INST OF CHINA ELECTRONICS TECH GRP

Botnet process resource recovery method and system, medium and product

The invention discloses a zombie process resource recovery method and system, a medium and a product, and the method comprises the steps: periodically carrying out process state inspection on continuous processes of an operating system, and adding process information of the continuous processes in a zombie state into a global zombie process chain table; selecting one piece of process information from the process information of the global zombie process chain table as current processing information, judging whether a corresponding target process meets a process recovery condition or not according to the information, and if the condition is met, directly executing resource recovery operation on the target process by a kernel; and processing the next piece of process information in the global zombie process chain table after the subsequent processing is completed, and if the condition is not met, continuing to process the next piece of process information in the global zombie process chain table. According to the method, the zombie process is directly recovered through the kernel, the business service interruption of the parent process is not caused, and the safe and effective recovery of the zombie process is realized.
Owner:KYLIN CORP

Denial of service attack analysis method, device, equipment, medium and product

The invention discloses a denial of service attack analysis method, device and equipment, a medium and a product. The method comprises the following steps: acquiring a global attack analysis model issued by a central server and denial of service attack data of the central control server; the global attack analysis model is obtained by the hosts and the central server based on a federated learning mode; analyzing the denial of service attack data based on a global attack analysis model to obtain a central control server portrait; and according to the central control server portrait, simulating the zombie host to establish an encrypted communication connection with the central control server, receiving an encrypted denial of service attack instruction of the central control server, and decrypting and analyzing the encrypted denial of service attack instruction to obtain denial of service attack information of the central control server. According to the invention, precious attack information is provided for active defense of the denial of service attack, and the defense efficiency and effectiveness of the denial of service attack are improved.
Owner:CHINA MOBILE (XIONGAN) ICT CO LTD +3