Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

13 results about "Zombie" patented technology

In computing, a zombie is a computer connected to the Internet that has been compromised by a hacker, computer virus or trojan horse program and can be used to perform malicious tasks of one sort or another under remote direction. Botnets of zombie computers are often used to spread e-mail spam and launch denial-of-service attacks (DOS attacks). Most owners of "zombie" computers are unaware that their system is being used in this way. Because the owner tends to be unaware, these computers are metaphorically compared to fictional zombies. A coordinated DDoS attack by multiple botnet machines also resembles a "zombie horde attack", as depicted in fictional zombie films.

AI large model fused API asset intelligent management method and system

The invention discloses an AI large model fused API asset intelligent management method and system, and relates to the technical field of API data security management, and the API asset intelligent management mainly comprises the following steps: (1) carrying out multi-source API data collection and preprocessing; (2) on the basis of the preprocessed API data, extracting API features by fusing natural language processing and flow feature analysis, and generating an API comprehensive feature vector fusing API document features and flow features; and (3) identifying API assets based on the API comprehensive feature vector, firstly identifying normal API assets to form an enterprise API asset list, and then identifying shadow APIs and zombie APIs based on the enterprise API asset list. According to the scheme, the accuracy of API asset identification can be improved; meanwhile, a deep learning model and algorithm are adopted, features can be automatically learned and extracted, manual intervention is reduced, and efficiency is improved; moreover, according to the scheme of the invention, intelligent identification and anomaly detection of API assets can be realized, shadow APIs and zombie APIs can be found in time, and the security and stability of the system are guaranteed.
Owner:THE THIRD RES INST OF MIN OF PUBLIC SECURITY +1

A method, system, device and storage medium for handling wild pointers

Embodiments of the present application disclose a wild pointer processing method, system, device and storage medium. According to the type information of each memory object, the technical solution provided by the embodiments of the present application determines the memory object of a specified type as a target memory object; then in the case of releasing the target memory object, a target zombie object is created, the instruction set architecture pointer of the target memory object is modified, and the instruction set architecture pointer is pointed to the target zombie object; and then the target zombie object is saved to the application memory, so that when the calling party uses the instruction set architecture pointer to call the target memory object, the calling party is intercepted based on the target zombie object through a message forwarding mechanism, and the calling logic is processed. By using the above technical means, the wild pointer processing of the online running environment of the application program can be realized, the application program can be prevented from crashing, the running effect of the application program is optimized, and the user experience is improved.
Owner:BIGO TECH PTE LTD

Botnet management method and device based on deep protocol reverse analysis and storage medium

Embodiments of the present disclosure provide a botnet management method and device based on deep protocol reverse analysis, which comprises: deploying a plurality of high-interaction honeypots in a virtual machine or a container, simulating real operating systems, application services or Internet of Things devices to trap bot nodes; obtaining data packets between the bot nodes and the honeypots, reverse analyzing the communication protocols in the data packets to obtain protocol analysis results; based on the protocol analysis results, constructing a virtual C&C communication network to simulate the communication protocols of the attackers to send fake instructions to the connected bot nodes; recording the node information connected to the virtual C&C communication network, and constructing a node relationship graph based on the node information; and identifying abnormal behavior patterns based on the node relationship graph, triggering a defense mechanism or a countermeasure mechanism when an abnormal behavior is detected. The present scheme not only can discover and analyze bot nodes when encountering botnet attacks, but also can counterattack and attack the attackers through an active virtual command and control network.
Owner:NO 15 INST OF CHINA ELECTRONICS TECH GRP

Methods, systems, and apparatuses for query analysis and classification

Described herein are methods, systems, and apparatuses for query analysis and classification. A plurality of entity identifier queries associated with a plurality of entity identifiers may be received and classified as being legitimate or illegitimate. Illegitimate entity identifier queries may be associated with originating devices that are infected with malware. The originating devices may have sent the illegitimate entity identifier queries in an attempt to communicate with a command and control server(s) of a botnet. Such originating devices may be identified and one or more remedial actions may be performed.
Owner:COMCAST CABLE COMM LLC

MCP flooding attack detection method based on behavior characteristics

An MCP flooding attack detection method based on behavior characteristics comprises the following steps: collecting and learning a large amount of legal MCP traffic, extracting parameter length, request interval, nesting depth and response time characteristics, and constructing four-dimensional normal distribution as a legal traffic model based on the parameters, the request interval, the nesting depth and the response time characteristics; the probability density of the feature vector of each new request under the legal model is calculated to judge the abnormal request and the attack type thereof, finally, an SIR infectious disease dynamic model and an ARIMA time sequence model are further innovatively integrated to predict the zombie node scale and the attack trend, and the prediction result is used as input to automatically trigger and adjust a defense strategy; according to the method, botnet attack detection is carried out on the large language model integrated with the MCP protocol by utilizing the multi-dimensional behavior characteristics, so that attack detection and an adaptive defense strategy are effectively realized, and a security protection capability is also provided for a complex network environment in which the large language model is integrated with the MCP protocol; the invention further comprises a system, equipment and a storage medium for implementing the method.
Owner:XI'AN PETROLEUM UNIVERSITY

Mobile devices with zombie mode

This provides mobile devices that allow the use of NFC authentication functions (such as Apple Pay and Suica) even when the battery is completely dead. [Solution] The mobile device 1 includes a battery 10, an NFC chip 141, an SE chip 190, an NFC utilization processing unit 191, and a power generation unit 200 that converts vibration into electricity. Even when the battery 10 is completely depleted, if the user shakes the mobile device 1 immediately before using the NFC authentication function, the power from the power generation unit 200 will wake up the NFC chip 141. Subsequent power for short-range wireless communication and driving the SE chip 190, etc., is supplied by the power passively generated by the NFC chip 141 due to an external magnetic field. Therefore, the user can use the NFC authentication function even when the battery 10 and backup power are completely depleted.
Owner:HATSUMEIYA

Method, device and electronic equipment for determining a botnet master

PendingCN122339736AAttackEngineering
This disclosure provides a method for identifying the master controller of a botnet, relating to the field of network security technology, particularly attack attribution, botnets, and deep learning. The specific implementation scheme is as follows: In response to the detection of attack traffic targeting external communication addresses, a set of controlled hosts corresponding to the attack traffic is determined, and network flow data of each controlled host within a preset attack attribution time window is extracted; for any controlled host, botnet feature preprocessing is performed on the network flow data to generate host behavior description information; the host behavior description information of each controlled host is input into a large language model in the security field, and through the prompt information configured for botnet feature analysis in the large language model, a list of suspected master controllers corresponding to each controlled host is output; the lists of suspected master controllers of each controlled host are aggregated, attack correlation analysis is performed, and the target botnet master controller is determined based on the analysis results.
Owner:BEIJING BAIDU NETCOM SCI & TECH CO LTD

Classification-based suppression and blocking methods and systems for botnets with different communication architectures

The present invention provides a method and system for classifying and suppressing zombie networks facing different communication architectures, which relates to the field of network security technology. The method includes: determining an implementable suppression channel according to control instructions, heartbeat mechanisms, and data synchronization characteristics, in combination with the protocol characteristics and network structure to which they belong; matching a corresponding blocking scheme based on the suppression channel; the blocking scheme is selected according to the communication architecture type of the zombie network, and the communication architecture type includes centralized control C2 communication type, peer-to-peer P2P communication type, and hybrid type; implementing blocking measures matching the blocking scheme through policy scheduling, adjusting the suppression blocking intensity according to network feedback, coordinating multi-point linkage operations, and evaluating the blocking effect at the same time. The present invention enhances the ability to govern zombie networks in cyberspace by effectively cutting off and interfering with the communication links of centralized control communication type, peer-to-peer communication type, and hybrid type zombie networks.
Owner:CHINA INFORMATION TECH SECURITY EVALUATION CENT +1

System

A system is provided.SOLUTION: A system comprising: an augmented reality device worn by a user; a sensor configured to detect a motion of the user; a display unit configured to receive data from a server and perform augmented reality display; a communication unit configured to communicate with the server and acquire an appearance position and timing of a zombie; and a determination unit configured to determine the motion of the user and display a reaction of the zombie based on a motion determination result.SELECTED DRAWING: Figure 1
Owner:SOFTBANK GROUP CORP

Botnet management method and device based on deep protocol reverse analysis

The embodiment of the invention provides a Botnet management method and device based on deep protocol reverse analysis. The method comprises the following steps: deploying a plurality of high-interaction honeypots in a virtual machine or a container, simulating a real operating system, application service or Internet of Things equipment, and trapping Botnet nodes; acquiring a data packet between the zombie node and the honeypot, and performing reverse analysis on a communication protocol in the data packet to obtain a protocol analysis result; constructing a virtual Camp based on a protocol analysis result; c, the communication network simulates a communication protocol of an attacker to send a forged instruction to the connected zombie node; the record is connected to the virtual Camp; c, communicating node information of the network, and constructing a node relation graph based on the node information; and identifying an abnormal behavior mode based on the node relation graph, and triggering a defense mechanism or a countering mechanism when an abnormal behavior is detected. According to the scheme, when the botnet attack is encountered, the botnet node can be found and analyzed, and an attacker can be countered and attacked through an active virtual command and a control network.
Owner:NO 15 INST OF CHINA ELECTRONICS TECH GRP

Botnet process resource recovery method and system, medium and product

The invention discloses a zombie process resource recovery method and system, a medium and a product, and the method comprises the steps: periodically carrying out process state inspection on continuous processes of an operating system, and adding process information of the continuous processes in a zombie state into a global zombie process chain table; selecting one piece of process information from the process information of the global zombie process chain table as current processing information, judging whether a corresponding target process meets a process recovery condition or not according to the information, and if the condition is met, directly executing resource recovery operation on the target process by a kernel; and processing the next piece of process information in the global zombie process chain table after the subsequent processing is completed, and if the condition is not met, continuing to process the next piece of process information in the global zombie process chain table. According to the method, the zombie process is directly recovered through the kernel, the business service interruption of the parent process is not caused, and the safe and effective recovery of the zombie process is realized.
Owner:KYLIN CORP

Denial of service attack analysis method, device, equipment, medium and product

The invention discloses a denial of service attack analysis method, device and equipment, a medium and a product. The method comprises the following steps: acquiring a global attack analysis model issued by a central server and denial of service attack data of the central control server; the global attack analysis model is obtained by the hosts and the central server based on a federated learning mode; analyzing the denial of service attack data based on a global attack analysis model to obtain a central control server portrait; and according to the central control server portrait, simulating the zombie host to establish an encrypted communication connection with the central control server, receiving an encrypted denial of service attack instruction of the central control server, and decrypting and analyzing the encrypted denial of service attack instruction to obtain denial of service attack information of the central control server. According to the invention, precious attack information is provided for active defense of the denial of service attack, and the defense efficiency and effectiveness of the denial of service attack are improved.
Owner:CHINA MOBILE (XIONGAN) ICT CO LTD +3