发明申请
US20060256729A1 Method and apparatus for identifying and disabling worms in communication networks
审中-公开
在通信网络中识别和禁用蠕虫的方法和装置
- 专利标题: Method and apparatus for identifying and disabling worms in communication networks
- 专利标题(中): 在通信网络中识别和禁用蠕虫的方法和装置
-
申请号: US11125446申请日: 2005-05-10
-
公开(公告)号: US20060256729A1公开(公告)日: 2006-11-16
- 发明人: David Chen , Edward Amoroso
- 申请人: David Chen , Edward Amoroso
- 主分类号: H04J1/16
- IPC分类号: H04J1/16
摘要:
A method and apparatus for enabling a network security service and network security infrastructure to detect, identify, mitigate, neutralize, and disable worms through distributed worm probes that can be linked to centralized monitoring systems for emergency response process is disclosed. The worm probes track packets with destination unreachable errors on a per source IP address basis. In one embodiment, when the number of such errors exceeds a predefined local threshold, e.g., within a predefined local time period at a worm probe, the count of such errors as well as the source IP address will be sent to all other worm probes in the network as an alert. When the number of such errors exceeds a predefined global threshold, e.g., within a predefined global time period, traffic from the endpoint device with the identified source IP address will be blocked to prevent that endpoint device from spreading worms further.
信息查询