发明名称 System and method of virus containment in computer networks
摘要 A method for detecting malicious activity in a computer network including deploying one or more suspicious event sensors, each sensor operative to detect a predefined suspicious event on at least one computer, logging any suspicious events detected by the sensors during normal operation of the network when no malicious activity is present, calculating a statistical distribution of the logged events, comparing the results of the event sensors to the statistical distribution and determining the probability of the result against a predefined threshold, and activating any of an alarm and a defense mechanism where the probability exceeds the predefined threshold.
申请公布号 US2004111632(A1) 申请公布日期 2004.06.10
申请号 US20030429248 申请日期 2003.05.05
申请人 HALPERIN AVNER 发明人 HALPERIN AVNER
分类号 G06F21/00;H04L12/24;H04L12/26;H04L29/06;(IPC1-7):G06F11/30;G06F15/173 主分类号 G06F21/00
代理机构 代理人
主权项
地址