发明名称 Heuristic detection and termination of fast spreading network worm attacks
摘要 Methods, apparati, and computer program products for detecting and responding to fast-spreading network worm attacks include a network monitoring module ( 110 ), which observes ( 205 ) failed network connection attempts from multiple sources. A logging module ( 120 ) logs ( 220 ) the failed connection attempts. An analysis module ( 150 ) uses the logged data on the failed connection attempts to determine ( 225 ) whether a sources is infected with a worm using a set of threshold criteria. The threshold criteria indicate whether a source's failed connection attempts are non-normal. In one embodiment, a response module ( 160 ) responds ( 240 ) to the computer worm by, e.g., alerting a user or system administrator, terminating an infected process ( 20 ), or terminating the infected source's network access.
申请公布号 US7159149(B2) 申请公布日期 2007.01.02
申请号 US20020280586 申请日期 2002.10.24
申请人 SYMANTEC CORPORATION 发明人 SPIEGEL MARK;MCCORKENDALE BRUCE;SOBEL WILLIAM
分类号 G06F11/00;G06F21/00 主分类号 G06F11/00
代理机构 代理人
主权项
地址