IP Library Granted Patent US 10,462,159
Granted Patent B2
US 10,462,159 · App. 15/190,093 · Granted Oct 29, 2019

Botnet detection system and method

Inventors: Masayuki Inoue (East Palo Alto, CA); Satoshi Iitsuka (East Palo Alto, CA); Yuhei Kawakoya (East Palo Alto, CA)
Assignee: NTT INNOVATION INSTITUTE, INC.
H04L63/1416C10M135/36H04L63/1425H04L63/1433H04L63/1458C10M2219/104C10N2230/36C10N2240/042C10N2240/10C10N2240/30H04L2463/144
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,462,159
App. No.
15/190,093
Granted
Oct 29, 2019
Kind
B2
Abstract

A system and method are provided for detecting a botnet in a network based on traffic flow, daisy chained mechanism and white-list generation mechanism. The system and method uses the known malicious components in a botnet such as IP address, domain name and URL, to be the root of a daisy chain and creates a network graph based on given traffic flow data such as NetFlow data, DNS cache data, DNS sinkhole data, DDoS data and Attack log data in threat sensors. The system and method iteratively detects new malicious factors by tracing that network graph. The system and method also introduces a technique to create a white list which is used in the daisy chain to reduce false positive.

Claims (21)

1. A botnet detection system, comprising:

a network having one or more nodes and one or more command and control devices coupled to each other;

a storage device having a plurality of pieces of data about the network including a plurality of internet protocol addresses with each internet protocol address corresponding to one of a node, a command and control devices and at least one known botnet and network traffic flow data indicating a communication between one of at least one node and at least one command and a communication and at least one known botnet and a domain name service cache; and

a botnet detection component coupled to the storage device, the botnet detection component detecting a new botnet by matching the network traffic flow data against an IP address of the at least one known botnet.

2. The system of claim 1 , wherein the network traffic flow data further comprises NetFlow data, DNS cache data, DNS sinkhole traffic, DDoS traffic and an attack log in sensors.

3. The system of claim 1 , wherein the botnet detection component stores data about the detected new botnet, the data including an internet protocol address of the detected new botnet, a domain name of the detected new botnet and a uniform resource locator of the detected new botnet.

4. The system of claim 3 , wherein the botnet detection component iteratively detects one or more additional new botnets based on the stored data about the detected new botnet.

5. The system of claim 1 , wherein the botnet detection component detects the new botnet by comparing the network traffic data against a white-list.

6. The system of claim 5 , wherein the white-list is a famous white-list.

7. The system of claim 5 further comprising a whitelist generator component that generates the whitelist based on a total number of nodes that communicate with a destination internet protocol address.

8. The system of claim 5 further comprising a whitelist scoring component that generates the white-list based on a ratio of the zombie nodes and non-zombie nodes that communicate with an unknown internet protocol address.

9. A botnet detection method, the method comprising:

obtaining a plurality of pieces of data about a network having one or more nodes and one or more command and control devices, the plurality of pieces of data comprising a plurality of internet protocol addresses with each internet protocol address corresponding to one of a node, a command and control devices and at least one known botnet and network traffic flow data indicating a communication between one of at least one node and at least one command and a communication and at least one known botnet and a domain name service cache; and

detecting, using the network traffic flow data, a new botnet by matching the network traffic flow data against an IP address of the at least one known botnet.

10. The method of claim 9 , wherein the network traffic pattern data further comprises netflow data, DNS cache data, DNS sinkhole traffic, DDoS traffic and an attack log in sensors.

11. The method of claim 9 further comprising storing data about the detected new botnet, the data including an internet protocol address of the detected new botnet, a domain name of the detected new botnet and a uniform resource locator of the detected new botnet.

12. The method of claim 11 further comprising iteratively detecting one or more additional new botnets based on the stored data about the detected new botnet.

13. The method of claim 9 , wherein detecting the new botnet further comprises comparing the network traffic data against a white-list.

14. The method of claim 13 , wherein the white-list is a famous white-list.

15. The method of claim 13 further comprising creating the white-list based on a total number of nodes that communicate with a destination internet protocol address.

16. The method of claim 13 further comprising creating the white-list based on a ratio of the zombie nodes and non-zombie nodes that communicate with an unknown internet protocol address.

Assignments (2)
CHANGE OF NAME Recorded Apr 14, 2020
From: NTT INNOVATION INSTITUTE, INC.
To: NTT RESEARCH, INC.
Reel/Frame 052396/0582 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 18, 2017
From: INOUE, MASAYUKI; IITSUKA, SATOSHI; KAWAKOYA, YUHEI
To: NTT INNOVATION INSTITUTE, INC.
Reel/Frame 044426/0950 →
Continuity (1)
Related Publication 20170374084A1 · Dec 28, 2017
Cited By (2)
US 12,401,681 US 12,406,185