×

Method and system for statistical analysis of botnets

  • US 8,468,601 B1
  • Filed: 02/27/2009
  • Issued: 06/18/2013
  • Est. Priority Date: 10/22/2008
  • Status: Active Grant
First Claim
Patent Images

1. A method for updating a botnet based on statistical data, the method comprising:

  • (a) acquiring, by a computer, botnet distribution of message size-based and timestamp-based statistics for all messages, including any non-spare messages, received from a known botnet over a time period, without acquiring contents of the messages from a remote server;

    (b) analyzing the botnet distribution statistics based on messages and determining an activity pattern of the botnet based on the botnet distribution statistics of a number of messages, with timestamps of the messages from the botnet distributed into a set of time intervals;

    (c) acquiring a continuous host distribution of message size-based statistics or timestamp-based statistics for all messages received from a single host over the time period, without acquiring contents of the messages from the remote server;

    (d) analyzing the host distribution statistics and determining a distribution pattern of the single host, with timestamps of the messages from the single host distributed into a set of time intervals, based on the host distribution statistics;

    (e) comparing the distribution statistics of the botnet with the distribution statistics of the single host; and

    (f) determining if the single host belongs to the botnet based on a degree of similarity of the distribution statistics and a similarity of their approximating functions.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×