发明名称 System and method for detection and mitigation of network worms
摘要 An intrusion detection system for a computer network includes a knowledge database that contains a baseline of normal host behavior, and a correlation engine that monitors network activity with reference to the knowledge database. The correlation engine accumulating information about anomalous events occurring on the network and then periodically correlating the anomalous events. The correlation engine generates a worm outbreak alarm when a certain number of hosts exhibit a role-reversal behavior. It is emphasized that this abstract is provided to comply with the rules requiring an abstract that will allow a searcher or other reader to quickly ascertain the subject matter of the technical disclosure. It is submitted with the understanding that it will not be used to interpret or limit the scope or meaning of the claims.
申请公布号 US2006242705(A1) 申请公布日期 2006.10.26
申请号 US20050114575 申请日期 2005.04.26
申请人 CISCO TECHNOLOGY, INC. 发明人 SADHASIVAM KARTHIKEYAN M.;ZHANG SHUGUANG;VARANASI RAVI K.
分类号 G06F12/14 主分类号 G06F12/14
代理机构 代理人
主权项
地址