Patent №
US 9,602,525
Granted
2017-03-21
Filed 2015
Owner
CISCO TECHNOLOGY, INC.
Lab
—
AI components
2
kr · hardware
Assignment
Recorded
Dataset
AIPD
2023_r1 edition
Application
14633805
Techniques are presented herein that combine a host-based analysis of an executable file on a host computer with a network-based analysis, i.e., an analysis of domain names to detect malware generated domain names that are used by the malicious executable files to establish malicious network connections. A server receives information from a host computer about an executable file that, when executed on the host computer, initiates a network connection. The server also receives information about the network connection itself. The server analyzes the information about the executable file to determine whether the executable file has a malicious disposition. Depending on a disposition of the executable file, the server analyzes the information about the network connection and determines whether the network connection is malicious.
AI classification
Ownership
CISCO TECHNOLOGY, INC.
assignment · 350550554
Assignors
QIAN, JIANG, O'DONNELL, ADAM J., FRANK, PAUL, MULLEN, PATRICK
On an employer assignment, the assignors are typically the inventors.