1461145189-101a8ef7-c02f-41d8-8139-02aadb5199f1

1. A method of detecting color print jobs of neutral gray color for converting a RIPped bitmap of black only to composite black during job workflow before printing comprising:
raster image processing of an input job where a pixel is color inspected;
detecting the pixel as black channel only or four color of CMYK channels;
converting the one plane per pixel of black channel to form planes per pixel of CMYK neutral gray; and,
printing the input job as the converted four planes per page of CMYK neutral gray.
2. The method of claim 1 wherein the detected input job as the one plane per page of black channel only is billed to a customer as a K-only page.
3. The method of claim 1 wherein the raster image processing processes an equal RGB input job as the one plane per page of black channel only.
4. The method of claim 3 wherein the equal RGB input job is detected as the K-only page.
5. The method of claim 1 where individual pixels of all the pages in a job are detected to be K-only or color.
6. A color print job processing method comprises:
detecting the job to include a K-only page during job workflow;
converting the K-only page to a contone composite black;
printing the K-only page as the contone composite black; and
billing the printed page as K-only.
7. The method of claim 6 wherein the converting comprises converting a raster image processed image bitmap to contone data.
8. The method of claim 6 wherein the converting comprises conversion from contone K-only to contone composite black based on color mode and resolution of job.
9. A color print job processing method comprises:
detecting a pixel in a job as K-only pixel during job workflow;
converting the K-only pixel to a contone composite black;
printing the K-only pixel as the contone composite black;
counting a total number of color pixels in the job; and,
billing the job based on the total number of color pixels counted.
10. The method of claim 8 wherein the converting comprises converting raster image processed image bitmap to contone data.
11. The method of claim 9 wherein the converting comprises conversion from contone K-only to contone composite black based on color mode and resolution of job.
12. A xerographic, inkjet or solid inkjet printing apparatus including a processor for detecting a print job as having a K-only page from raster image processing, and for converting the K-only page to contone composite black during job workflow, whereby the K-only page is billed as K-only and printed as composite black.
13. A xerographic, inkjet or solid inkjet printing apparatus including a processor for detecting the pixels in a page of a print job as having a K-only pixels from raster image processing and for converting the K-only pixel to contone composite black during job workflow, whereby the K-only pixels are billed as K-only and printed as composite black.

The claims below are in addition to those above.
All refrences to claim(s) which appear below refer to the numbering after this setence.

1. A method for detecting Fast-Flux malware, the method comprising:
monitoring by a network traffic monitor a plurality of domain name system (DNS) lookup requests to one or more DNS servers initiated by one or more network devices in a local area network (LAN) to a wide area network (WAN), the DNS lookup requests comprising a plurality of requests to resolve one or more uniform resource locators (URLs) to one or more received network addresses (IP);
monitoring the one or more received network addresses (IP) resolved for the one or more URLs to provide a URL-to-IP associations list, wherein the URL-to-IP associations list is configured to store one or more suspicious URLs;
monitoring the one or more DNS servers used for the DNS lookup requests for resolving the URLs to provide a DNS Domain-to-DNS server associations list;
generating a suspicious URL log based on the URL-to-IP associations list and a suspicious DNS log based on the DNS Domain-to-DNS server associations list;
determining whether a designated suspicious URL from the suspicious URL log matches designated data in the suspicious DNS log; and
after determining that the designated suspicious URL from the suspicious URL log matches the designated data in the suspicious DNS log, generating an event indicating a combination of flux actions are active.
2. The method of claim 1, further comprising indicating a presence of a malware program in the LAN based on the suspicious DNS log and the suspicious URL log.
3. The method of claim 1, further comprising:
configuring a resource association list comprising the URL-to-IP associations list or the DNS Domain-to-DNS server associations list; and
configuring a suspicious resource log comprising the suspicious URL log or the suspicious DNS log.
4. The method of claim 3, further comprising:
counting a total number of association changes in the resource association list; and
logging the suspicious resource log, if the total number of association changes is greater than a total-association-change threshold.
5. The method of claim 3, further comprising:
counting a number of association changes in the resource association list in a time-period; and
logging the suspicious resource log, if the number of association changes in the time-period is greater than a time-period-association-changes threshold.
6. The method of claim 3, further comprising:
calculating an association change frequency of the resource association list; and
logging the suspicious resource log, if the association change frequency is greater than an association-change-frequency threshold.
7. The method of claim 3, further comprising:
calculating a pattern in the resource association list; and
logging the suspicious resource log, if the pattern is found among a pattern history.
8. A system for detecting Fast-Flux malware, the system comprising:
at least one hardware processor; and
a network traffic monitor operating on the at least one hardware processor and configured to:
monitor a plurality of domain name system (DNS) lookup requests to one or more DNS servers initiated by one or more network devices in a local area network (LAN) to a wide area network (WAN), the DNS lookup requests comprising a plurality of requests to resolve one or more uniform resource locators (URLs) to one or more received network addresses (IP);
monitor the one or more received network addresses (IP) resolved for resolving the one or more URLs to provide a URL-to-IP associations list;
monitor the one or more DNS servers used for the DNS lookup requests for resolving the URLs to provide a DNS Domain-to-DNS server associations list; and

a malware detector configured to:
generate a suspicious URL log based on the URL-to-IP associations list and a suspicious DNS log based on the DNS Domain-to-DNS server associations list;
determine whether a designated suspicious URL from the suspicious URL log matches designated data in the suspicious DNS log;
after determining that the designated suspicious URL from the suspicious URL log matches the designated data in the suspicious DNS log, generate an event indicating a combination of flux actions are active; and
indicate a presence of a malware program in the LAN based on the suspicious URL log and the suspicious DNS log.
9. The system of claim 8, wherein:
a resource association list comprises the URL-to-IP associations list or the DNS Domain-to-DNS server associations list; and
a suspicious resource log comprises the suspicious URL log or the suspicious DNS log.
10. The system of claim 9, wherein the malware detector is further configured to:
count a total number of association changes in the resource association list; and
log the suspicious resource log, if the total number of association changes is greater than a total-association-change threshold.
11. The system of claim 9, wherein the malware detector is further configured to:
count a number of association changes in the resource association list in a time-period; and
log the suspicious resource log, if the number of association changes in the time-period is greater than a time-period-association-changes threshold.
12. The system of claim 9, wherein the malware detector is further configured to:
calculate an association change frequency of the resource association list; and
log the suspicious resource log, if the association change frequency is greater than an association-change-frequency threshold.
13. The system of claim 9, wherein the malware detector is further configured to:
calculate a pattern in the resource association list; and
log the suspicious resource log, if the pattern is found among a pattern history.
14. A non-transitory computer readable storage medium comprising computer-executable instructions for detecting Fast-Flux malware, the computer-executable instructions comprising:
monitoring by a network traffic monitor a plurality of domain name system (DNS) lookup requests to one or more DNS servers initiated by one or more network devices in a local area network (LAN) to a wide area network (WAN), the DNS lookup requests comprising a plurality of requests to resolve one or more uniform resource locators (URLs) to one or more received network addresses (IP);
monitoring the one or more received network addresses (IP) resolved for resolving the one or more URLs to provide a URL-to-IP associations list;
monitoring the one or more DNS servers used for the DNS lookup requests for resolving the URLs to provide a DNS Domain-to-DNS server associations list;
generate a suspicious URL log based on the URL-to-IP associations list and a suspicious DNS log based on the DNS Domain-to-DNS server associations list;
determining whether a designated suspicious URL from the URL-to-IP associations list matches designated data in the DNS Domain-to-DNS server associations list; and
after determining that the designated suspicious URL from the URL-to-IP associations list matches the designated data in the DNS Domain-to-DNS server associations list, generating an event indicating a combination of flux actions are active.
15. The non-transitory computer readable storage medium of claim 14, further comprising computer-executable instructions comprising: indicating a presence of a malware program in the LAN based on the suspicious DNS log or the suspicious URL log.
16. The non-transitory computer readable storage medium of claim 14, further comprising computer-executable instructions comprising:
configuring a resource association list comprising the URL-to-IP associations list or the DNS Domain-to-DNS server associations list; and
configuring a suspicious resource log comprising the suspicious URL log or the suspicious DNS log.
17. The non-transitory computer readable storage medium of claim 16, further comprising computer-executable instructions comprising:
counting a total number of association changes in the resource association list; and
logging the suspicious resource log, if the total number of association changes is greater than a total-association-change threshold.
18. The non-transitory computer readable storage medium of claim 16, further comprising computer-executable instructions comprising:
counting a number of association changes in the resource association list in a time-period; and
logging the suspicious resource log, if the number of association changes in the time-period is greater than a time-period-association-changes threshold.
19. The non-transitory computer readable storage medium of claim 16, further comprising computer-executable instructions comprising:
calculating an association change frequency of the resource association list; and
logging the suspicious resource log, if the association change frequency is greater than an association-change-frequency threshold.
20. The non-transitory computer readable storage medium of claim 16, further comprising computer-executable instructions comprising:
calculating a pattern in the resource association list; and
logging the suspicious resource log, if the pattern is found among a pattern history.