METHOD AND APPARATUS FOR DETECTING HIDDEN NETWORK COMMUNICATION CHANNELS OF ROOTKIT TOOLS

Patent №

US 7,665,136

Granted

2010-02-16

Filed 2005

Owner

SYMANTEC CORPORATION

Lab

AI components

3

kr · planning · hardware

Assignment

Recorded

Dataset

AIPD

2023_r1 edition

Application

11271327

Methods and apparatuses for detecting hidden network channels of rootkit tools are described. In one embodiment, critical endpoint events detected at an endpoint computer system are selectively logged to an endpoint database. Also, critical network events associated with the endpoint computer system and detected on a network are selectively logged to a gateway database. Periodically some or all of the entries in the endpoint database are compared to entries in the gateway database. Entries detected at the network but not detected at the endpoint computer system are presumed indicative of hidden network channels of rootkit tools.

Knowledge representationPlanningAI hardwareH04L 63/1475G06F 21/566H04L 67/535G06F 2221/2101

AI classification

AI hardware0.99
Planning0.80
Knowledge representation0.59
Natural language0.05
Evolutionary computation0.01
Machine learning0.01
Vision0.01
Speech0.00

Ownership

SYMANTEC CORPORATION

assignment · 172310368

Assignors

SZOR, PETER

On an employer assignment, the assignors are typically the inventors.

© 2026 NYSGPT2525 LLC