PASSIVE DETECTION OF REBOOTING HOSTS IN A NETWORK
First Claim
Patent Images
1. A computer-implemented method for detecting host reboots passively, the computer-implemented method comprising:
- a) storing a list of one or more host initialization events, each of the one or more host initialization events being associated with a host system;
b) receiving packet destination information derived from packets sourced from the host system;
c) comparing the received packet destination information with the list of one or more host initialization events to determine whether any matches occur;
d) incrementing the value of a count variable if a match is determined to exist, otherwise, maintaining the count variable at its current value; and
e) determining whether one or more reboots of the host occurred using the value of the count variable.
2 Assignments
0 Petitions
Accused Products
Abstract
Host reboots may be detected passively by tracking and analyzing host initialization events and/or by tracking and analyzing temporal skews in periodic events. Detected host reboots may then be used to determine or help determine whether or not the host has a possible malware infection.
-
Citations
23 Claims
-
1. A computer-implemented method for detecting host reboots passively, the computer-implemented method comprising:
-
a) storing a list of one or more host initialization events, each of the one or more host initialization events being associated with a host system; b) receiving packet destination information derived from packets sourced from the host system; c) comparing the received packet destination information with the list of one or more host initialization events to determine whether any matches occur; d) incrementing the value of a count variable if a match is determined to exist, otherwise, maintaining the count variable at its current value; and e) determining whether one or more reboots of the host occurred using the value of the count variable. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11)
-
-
12. Apparatus for detecting host reboots passively, the apparatus comprising:
-
a) means for storing a list of one or more host initialization events, each of the one or more host initialization events being associated with a host system; b) means for receiving packet destination information derived from packets sourced from the host system; c) means for comparing the received packet destination information with the list of one or more host initialization events to determine whether any matches occur; d) means for incrementing the value of a count variable if a match is determined to exist, otherwise, maintaining the count variable at its current value; and e) means for determining whether one or more reboots of the host occurred using the value of the count variable. - View Dependent Claims (13)
-
-
14. A computer-implemented method for detecting host reboots passively, the computer-implemented method comprising:
-
a) accepting information of packet flows for the host system, wherein each of the packet flows corresponds to one or more events, and wherein a plurality of packet flows corresponding to a given one of the one or more events exhibit periodicity; b) determining, for each of the one or more events, whether or not the event exhibits a phase change using the corresponding plurality of packet flows; and c) determining whether one or more reboots of the host occurred using the determination of whether or not the event exhibits a phase change. - View Dependent Claims (15, 16, 17, 18, 19, 20, 21)
-
-
22. Apparatus for detecting host reboots passively, the apparatus comprising:
-
a) means for accepting information of packet flows for the host system, wherein each of the packet flows corresponds to one or more events, and wherein a plurality of packet flows corresponding to a given one of the one or more events exhibit periodicity; b) means for determining, for each of the one or more events, whether or not the event exhibits a phase change using the corresponding plurality of packet flows; and c) means for determining whether one or more reboots of the host occurred using the determination of whether or not the event exhibits a phase change. - View Dependent Claims (23)
-
Specification