发明名称 METHOD, APPARATUS, AND COMPUTER PROGRAM PRODUCT FOR DETECTING COMPUTER WORMS IN A NETWORK
摘要 A worm is a malicious process that autonomously spreads itself from one host to another. To infect a host, a worm must somehow copy itself to the host. The method in which a worm transmits a copy of itself produces network traffic patterns that can be generalized as a traffic behavior. As a worm spreads itself across the network, the propagation of the traffic behavior can be witnessed as hosts are infected, one after another. By monitoring the network traffic for propagations of traffic behaviors, a presence of a worm can be detected.
申请公布号 WO2006047137(A3) 申请公布日期 2009.02.26
申请号 WO2005US37381 申请日期 2005.10.19
申请人 THE MITRE CORPORATION;ELLIS, DANIEL, R. 发明人 ELLIS, DANIEL, R.
分类号 G06F7/04 主分类号 G06F7/04
代理机构 代理人
主权项
地址