发明名称 WORM DETECTION BY TRENDING FAN OUT
摘要 The invention detects stealth worm propagation by comparing the repeat elements in sets of destinations of a source in multiple time windows to a fitted distribution of same, stored as a benchmark plot. Measurements are performed over N time windows, wherein a representation of the set of destinations to which a respective source has sent packets is determined for each source, in each time window. The counting is performed using a hash table. Once N such sets of destinations have been obtained, the number X k of destinations that are common to N, N-1, N-2,..., 2, 7 windows is determined. Thus X kis the number of destinations that a particular source sent packets to in k time windows. X k is then compared to the corresponding value on the plot; anomalies indicate an attack from the respective source.
申请公布号 WO2008142666(A3) 申请公布日期 2009.06.11
申请号 WO2008IB53130 申请日期 2008.04.15
申请人 ALCATEL LUCENT;RABINOVITCH, PETER;CHOW, STANLEY TAIHAI;BASSEM, ABDEL-AZIZ 发明人 RABINOVITCH, PETER;CHOW, STANLEY TAIHAI;BASSEM, ABDEL-AZIZ
分类号 H04L29/06;F16B31/02;F16B39/12;F16B39/28 主分类号 H04L29/06
代理机构 代理人
主权项
地址