发明名称 PROACTIVE WORM CONTAINMENT (PWC) FOR ENTERPRISE NETWORKS
摘要 A proactive worm containment (PWC) solution for enterprises uses a sustained faster-than-normal outgoing connection rate to determine if a host is infected. Two novel white detection techniques are used to reduce false positives, including a vulnerability time window lemma to avoid false initial containment, and a relaxation analysis to uncontain (or unblock) those mistakenly contained (or blocked) hosts, if there are any. The system integrates seamlessly with existing signature-based or filter-based worm scan filtering solutions. Nevertheless, the invention is signature free and does not rely on worm signatures. Nor is it protocol specific, as the approach performs containment consistently over a large range of worm scan rates. It is not sensitive to worm scan rate and, being a network-level approach deployed on a host, the system requires no changes to the host's OS, applications, or hardware.
申请公布号 WO2008079990(A4) 申请公布日期 2009.01.29
申请号 WO2007US88397 申请日期 2007.12.20
申请人 THE PENN STATE RESEARCH FOUNDATION;LIU, PENG;JHI, YOON-CHAN;LI, LUNQUAN 发明人 LIU, PENG;JHI, YOON-CHAN;LI, LUNQUAN
分类号 H04L29/06 主分类号 H04L29/06
代理机构 代理人
主权项
地址
您可能感兴趣的专利