首页> 外国专利> PROACTIVE WORM CONTAINMENT (PWC) FOR ENTERPRISE NETWORKS

PROACTIVE WORM CONTAINMENT (PWC) FOR ENTERPRISE NETWORKS

机译:企业网络的主动蠕虫控制(PWC)

摘要

A proactive worm containment (PWC) solution for enterprises uses a sustained faster-than-normal outgoing connection rate to determine if a host is infected. Two novel white detection techniques are used to reduce false positives, including a vulnerability time window lemma to avoid false initial containment, and a relaxation analysis to uncontain (or unblock) those mistakenly contained (or blocked) hosts, if there are any. The system integrates seamlessly with existing signature-based or filter-based worm scan filtering solutions. Nevertheless, the invention is signature free and does not rely on worm signatures. Nor is it protocol specific, as the approach performs containment consistently over a large range of worm scan rates. It is not sensitive to worm scan rate and, being a network-level approach deployed on a host, the system requires no changes to the host's OS, applications, or hardware.
机译:适用于企业的主动蠕虫遏制(PWC)解决方案使用比正常外发连接速率持续稳定的速度来确定主机是否被感染。两种新颖的白色检测技术可用于减少误报,包括避免出现错误的初始遏制的脆弱性时间窗口引理,以及用于松弛(包含或解除阻止)那些错误包含(或阻止)主机(如果有)的松弛分析。该系统与现有的基于特征码或基于过滤器的蠕虫扫描过滤解决方案无缝集成。然而,本发明是没有签名的,并且不依赖蠕虫签名。它也不是特定于协议的,因为该方法在很大范围的蠕虫扫描速率下始终执行遏制。它对蠕虫扫描速率不敏感,并且作为部署在主机上的网络级方法,系统无需更改主机的OS,应用程序或硬件。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号