首页> 外国专利> Heuristic Detection and Termination of Fast Spreading Network Worm Attacks

Heuristic Detection and Termination of Fast Spreading Network Worm Attacks

机译:快速传播网络蠕虫攻击的启发式检测和终止

摘要

Methods, apparati, and computer program products for detecting and responding to fast-spreading network worm attacks include a network monitoring module, which observes failed network connection attempts from multiple sources. A logging module logs the failed connection attempts. An analysis module uses the logged data on the failed connection attempts to determine whether a sources is infected with a worm using a set of threshold criteria. The threshold criteria indicate whether a source's failed connection attempts are non-normal. In one embodiment, a response module responds to the computer worm by, e.g., alerting a user or system administrator, terminating an infected process, or terminating the infected source's network access.
机译:用于检测和响应快速传播的网络蠕虫攻击的方法,设备和计算机程序产品包括网络监视模块,该模块监视来自多个源的失败的网络连接尝试。日志记录模块记录失败的连接尝试。分析模块使用失败连接尝试中的记录数据,使用一组阈值条件来确定源是否感染了蠕虫。阈值标准指示源的失败连接尝试是否不正常。在一个实施例中,响应模块通过例如警告用户或系统管理员,终止受感染的进程或终止受感染的源的网络访问来对计算机蠕虫作出响应。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号