×

Systems and methods for detecting communication channels of bots

  • US 8,561,177 B1
  • Filed: 11/30/2007
  • Issued: 10/15/2013
  • Est. Priority Date: 04/01/2004
  • Status: Active Grant
First Claim
Patent Images

1. A method for detecting a communication channel of a bot, comprising:

  • detecting presence of a suspected command and control communication channel between a first network device and a second network device, the suspected command and control communication channel having an increased probability of being used for bot communication;

    identifying the communication channel of the bot, the communication channel of the bot being a command and control communication channel permitting remote control of all or a portion of the second network device without authorization by a user of the second network device, the identifying comprising;

    scanning data flow within the detected suspected command and control communication channel for a bot communication;

    determining a first of a plurality of protocols and corresponding ports associated with the data flow; and

    determining if a suspected bot communication exists within the data flow by analyzing a response of a virtual machine to the data flow, the virtual machine being configurable with ports corresponding to any of the plurality of protocols including the first protocol associated with the data flow, the virtual machine configured with the corresponding ports associated with the data flow; and

    if a suspected bot communication is detected indicating existence of the communication channel of the bot, performing a recovery process.

View all claims
  • 7 Assignments
Timeline View
Assignment View
    ×
    ×