Pre-Grant Publication Number: 20070208822
Filing Date: March 01, 2006
Inventors: Yi-Min Wang, Douglas Beck
Assignee: Microsoft Corporation
Current U.S. Classification: 709, 709/217000
View Prior Art for Claim 00010
One or more processor-accessible media comprising processor-executable instructions that, when executed, direct a device to perform actions comprising:
visiting a uniform resource locator (URL) of a parent list of redirection URLs;
producing a child list of redirection URLs from the action of visiting;
recursively visiting child URLs of the child list of redirection URLs to discover redirection relationships of the URLs that are visited; and
creating a graph that includes the URLs that are visited and that indicates the discovered redirection relationships.
Submitted by: Kathy WangLast updated: 8 months ago
Title Using Honeyclients to Detect New Attacks
Description
Honeyclients are systems that drive a piece of vulnerable client software to potentially malicious sites, and monitor system behavior for indicators of compromise. Each honeyclient is a virtual host, and drives applications such as web browsers to user-specified URLs, looking for signs of malicious behavior when accessing that URL. The malicious behavior is flagged via an integrity check capability, which monitors for changes in files, registry key values, and processes. Upon detection of suspicious behavior, the honeyclient virtual machine is suspended, a new clone is created, and the spidering process continues.
2 thumbs up 0 thumbs down
Annotations(2)