发明名称 |
WORM DETECTION BY TRENDING FAN OUT |
摘要 |
The invention detects stealth worm propagation by comparing the repeat elements in sets of destinations of a source in multiple time windows to a fitted distribution of same, stored as a benchmark plot. Measurements are performed over N time windows, wherein a representation of the set of destinations to which a respective source has sent packets is determined for each source, in each time window. The counting is performed using a hash table. Once N such sets of destinations have been obtained, the number X k of destinations that are common to N, N-1, N-2,..., 2, 7 windows is determined. Thus X kis the number of destinations that a particular source sent packets to in k time windows. X k is then compared to the corresponding value on the plot; anomalies indicate an attack from the respective source. |
申请公布号 |
WO2008142666(A3) |
申请公布日期 |
2009.06.11 |
申请号 |
WO2008IB53130 |
申请日期 |
2008.04.15 |
申请人 |
ALCATEL LUCENT;RABINOVITCH, PETER;CHOW, STANLEY TAIHAI;BASSEM, ABDEL-AZIZ |
发明人 |
RABINOVITCH, PETER;CHOW, STANLEY TAIHAI;BASSEM, ABDEL-AZIZ |
分类号 |
H04L29/06;F16B31/02;F16B39/12;F16B39/28 |
主分类号 |
H04L29/06 |
代理机构 |
|
代理人 |
|
主权项 |
|
地址 |
|