发明名称 METHOD AND SYSTEM FOR IDENTIFYING ENTERPRISE NETWORK HOSTS INFECTED WITH SLOW AND/OR DISTRIBUTED SCANNING MALWARE
摘要 Malware detection systems are presented in which a list is constructed of enterprise hosts to or from which each given enterprise network host sends or receives packets within a current measurement period and statistics are accumulated based on two or more measurement period lists, with a count value being derived from the statistics to indicate the number of other hosts to or from which each monitored host sent or received packets, and one or more monitored hosts may be identified as suspected of being infected with slow and/or distributed scanning malware for which the count value exceeds a threshold value.
申请公布号 US2009293122(A1) 申请公布日期 2009.11.26
申请号 US20080124431 申请日期 2008.05.21
申请人 ALCATEL-LUCENT 发明人 ABDEL-AZIZ BASSEM;CHOW STANLEY;CHEN SHU-LIN
分类号 G06F11/00 主分类号 G06F11/00
代理机构 代理人
主权项
地址