发明名称 PROACTIVE WORM CONTAINMENT (PWC) FOR ENTERPRISE NETWORKS
摘要 A proactive worm containment (PWC) solution for enterprises uses a sustained faster-than-normal outgoing connection rate to determine if a host is infected. Two novel white detection techniques are used to reduce false positives, including a vulnerability time window lemma to avoid false initial containment, and a relaxation analysis to uncontain (or unblock) those mistakenly contained (or blocked) hosts, if there are any. The system integrates seamlessly with existing signature-based or filter-based worm scan filtering solutions. Nevertheless, the invention is signature free and does not rely on worm signatures. Nor is it protocol specific, as the approach performs containment consistently over a large range of worm scan rates. It is not sensitive to worm scan rate and, being a network-level approach deployed on a host, the system requires no changes to the host's OS, applications, or hardware.
申请公布号 US2009031423(A1) 申请公布日期 2009.01.29
申请号 US20070961062 申请日期 2007.12.20
申请人 LIU PENG;JHI YOON-CHAN;LI LUNQUAN 发明人 LIU PENG;JHI YOON-CHAN;LI LUNQUAN
分类号 G06F21/00 主分类号 G06F21/00
代理机构 代理人
主权项
地址