IP Library Granted Patent US 10,122,738
Granted Patent B2
US 10,122,738 · App. 15/215,311 · Granted Nov 6, 2018

Botnet detection system and method

Inventors: Ming-Kung Sun (New Taipei, TW); Chiung-Ying Huang (New Taipei, TW); Zong-Cyuan Jhang (New Taipei, TW)
Assignee: ACER INCORPORATED
H04L63/1416H04L63/101H04L63/1425H04L2463/144
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,122,738
App. No.
15/215,311
Granted
Nov 6, 2018
Kind
B2
Abstract

A botnet detection system and method are provided. The method includes the steps of: retrieving a network log file of a computer device; refining the network log file according to a device alive-time record of the computer device and a network white list to obtain a plurality of individual network log files, wherein each individual network log file records time information, a source IP address of the computer device, and an individual destination IP address; and analyzing a plurality of connection intervals of the source IP address connecting to the individual destination IP address in each individual network log file to determine whether the computer device exhibits connection behavior that indicates infection by a botnet malware.

Claims (21)

1. A botnet detection method, comprising:

retrieving a network log file of a computer device;

refining the network log file according to a device alive-time record of the computer device and a network white list to obtain a plurality of individual network log files, wherein each individual network log file records time information, a source IP address of the computer device, and an individual destination IP address;

calculating an average value and a standard deviation of the connection intervals of the source IP address connecting to the individual destination IP address in each individual network log file;

calculating a connection frequency feature value of each individual network log file by dividing the standard deviation by the average value;

determining whether the computer device exhibits connection behavior that indicates infection by a botnet malware according to the calculated connection frequency feature value;

if the connection frequency feature value of each individual network log file is larger than the predetermined threshold, determining that the computer device does not exhibit connection behavior that indicates infection by the botnet malware; and

if the connection frequency feature value of each individual network log file is smaller than the predetermined threshold, determining that the computer device exhibits connection behavior that indicates infection by the botnet malware.

2. The botnet detection method as claimed in claim 1 , further comprising:

determining whether the connection frequency feature value is smaller than a predetermined threshold.

3. A botnet detection system, comprising:

a memory unit, for storing a botnet detection program; and

a processor, configured to retrieve a network log file of a computer device, and execute the botnet detection program to analyze the network log file,

wherein the processor refines the network log file according to a device alive-time record of the computer device and a network white list to obtain a plurality of individual network log files, wherein each individual network log file records time information, a source IP address of the computer device, and an individual destination IP address,

wherein the processor further calculates an average value and a standard deviation of the connection intervals in each individual network log file, calculates a connection frequency feature value of each individual network log file by dividing the standard deviation by the average value,

wherein the processor further determines whether the computer device exhibits connection behavior that indicates infection by a botnet malware according to the calculated connection frequency value;

if the connection frequency feature value of each individual network log file is larger than the predetermined threshold, determining that the computer device does not exhibit connection behavior that indicates infection by the botnet malware; and

if the connection frequency feature value of each individual network log file is smaller than the predetermined threshold, determining that the computer device exhibits connection behavior that indicates infection by the botnet malware.

4. The botnet detection system as claimed in claim 3 , wherein the processor further determines whether the connection frequency feature value is smaller than a predetermined threshold.

5. The botnet detection system as claimed in claim 4 , wherein the processor further determines that the computer device does not exhibit connection behavior that indicates infection by the botnet malware if the connection frequency feature value of each individual network log file is larger than the predetermined threshold, and

the processor further determines that the computer device exhibits connection behavior that indicates infection by the botnet malware if the connection frequency feature value of each individual network log file is smaller than the predetermined threshold.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 27, 2019
From: ACER INCORPORATED
To: ACER CYBER SECURITY INCORPORATED
Reel/Frame 049616/0116 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 7, 2019
From: ACER CYBER SECURITY INCORPORATED
To: ACER INCORPORATED
Reel/Frame 049098/0268 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 22, 2019
From: ACER INCORPORATED
To: ACER CYBER SECURITY INCORPORATED
Reel/Frame 048954/0466 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 20, 2016
From: SUN, MING-KUNG; HUANG, CHIUNG-YING; JHANG, ZONG-CYUAN
To: ACER INCORPORATED
Reel/Frame 039202/0391 →
Priority Claims (1)
TW 105112772 A · Apr 25, 2016 · national
Continuity (1)
Related Publication 20170310687A1 · Oct 26, 2017
Cited By (1)
US 12,225,024