×

System and method for bot detection

  • US 9,628,498 B1
  • Filed: 10/11/2013
  • Issued: 04/18/2017
  • Est. Priority Date: 04/01/2004
  • Status: Active Grant
First Claim
Patent Images

1. A method for detecting a communication channel of a bot, comprising:

  • detecting a presence of the communication channel between a first network device and a second network device;

    scanning data associated with a data flow within the detected channel for a suspected bot communication, the scanning including analyzing content of the data associated with the data flow to detect whether the first network device is propagating malware;

    determining whether a potential bot communication exists within the data associated with the data flow;

    buffering at least a portion of the data associated with the data flow;

    providing at least the portion of the data associated with the data flow to a first simulation module of a plurality of simulation modules to determine whether a bot communication exists;

    generating an activity signature based on analysis by the first simulation module;

    storing the activity signature for use in subsequent analyses; and

    performing a recovery process when either the potential bot communication or the bot communication is detected, the recovery process including, determining one or more network devices that participated in communications using the communication channel operating as a command and control communication channel, the one or more network devices include at least the first network device.

View all claims
  • 6 Assignments
Timeline View
Assignment View
    ×
    ×