发明名称 Mechanism to correlate the presence of worms in a network
摘要 A method and a system for preventing a network attack, the attack being cause by the presence of worms in the network, is provided. The method includes determining the number of packets being transmitted from each source in the network to a plurality of destinations, the packets being transmitted from a source with a set of characteristics. If the number of packets with the set of characteristics, being transmitted from a source, exceeds a predefined first threshold, then the signature of the packets is stored. Subsequently, if at least one of the pluralities of destinations of the packets identified with the source becomes a source of new packets, the new packets being transmitted to more than one destination; then the new packets are compared with the signature. If at least one new packet matches with the signature, then the worm is to be detected.
申请公布号 US2007094730(A1) 申请公布日期 2007.04.26
申请号 US20050254592 申请日期 2005.10.20
申请人 CISCO TECHNOLOGY, INC. 发明人 BHIKKAJI BHARGAV;VENKAT BALAJI
分类号 G06F12/14 主分类号 G06F12/14
代理机构 代理人
主权项
地址