发明名称 System, method and program product for detecting unknown computer attacks
摘要 A computer system and program product for automatically determining if a packet is a new, exploit candidate. First program instructions determine if the packet is a known exploit or portion thereof. Second program instructions determine if the packet is network broadcast traffic presumed to be harmless. Third program instructions determine if the packet is network administration traffic. If the packet is a known exploit or portion thereof, network broadcast traffic, or network administration traffic, the packet is not considered a new, exploit candidate. If the packet is not a known exploit or portion thereof, network broadcast traffic, or network administration traffic, the packet is an exploit candidate. Alternately, the first program instructions determine if the packet is a known exploit or portion thereof. The second program instructions determine if the packet is network broadcast traffic presumed to be harmless. Third program instructions determine if the packet is another type presumed or known from experience to be harmless. If the packet is a known exploit or portion thereof, network broadcast traffic, or the other type, the packet is not considered a new, exploit candidate. If the packet is not a known exploit or portion thereof, network broadcast traffic, or the other type, the packet is an exploit candidate.
申请公布号 US8127356(B2) 申请公布日期 2012.02.28
申请号 US20030650440 申请日期 2003.08.27
申请人 THIELE FREDERIC G.;WALTER MICHAEL A.;INTERNATIONAL BUSINESS MACHINES CORPORATION 发明人 THIELE FREDERIC G.;WALTER MICHAEL A.
分类号 H04L29/14;G06F11/30;G06F21/00;H04L29/02;H04L29/06 主分类号 H04L29/14
代理机构 代理人
主权项
地址