发明名称 System and method of identifying the source of an attack on a computer network
摘要 The present invention provides a system and method of tracing the spread of computer malware in a communication network. One aspect of the present invention is a method that traces the spread of computer malware in a communication network. When suspicious data characteristic of malware is identified in a computing device connected to the communication network, the method causes data that describes the state of the computing device to be stored in a database. After a specific attack against the communication network is confirmed, computing devices that are infected with the malware are identified. Then, the spread of the malware between computing devices in the communication network is traced back to a source.
申请公布号 US2006070130(A1) 申请公布日期 2006.03.30
申请号 US20040951173 申请日期 2004.09.27
申请人 MICROSOFT CORPORATION 发明人 COSTEA MIHAI;AUCSMITH DAVID W.
分类号 G06F12/14 主分类号 G06F12/14
代理机构 代理人
主权项
地址