发明授权
- 专利标题: Rapidly propagating threat detection
- 专利标题(中): 快速传播威胁检测
-
申请号: US11184941申请日: 2005-07-19
-
公开(公告)号: US07873998B1公开(公告)日: 2011-01-18
- 发明人: Mark L. Wilkinson , Dirk Ourston
- 申请人: Mark L. Wilkinson , Dirk Ourston
- 申请人地址: US IL Chicago
- 专利权人: Trustwave Holdings, Inc.
- 当前专利权人: Trustwave Holdings, Inc.
- 当前专利权人地址: US IL Chicago
- 代理商 D'Ann Naylor Rifai; Mary Jo Bertani
- 主分类号: G08B23/00
- IPC分类号: G08B23/00 ; G06F15/173
摘要:
A method, system, apparatus, and computer-readable medium to detect rapidly propagating threats in a network. A rapidly propagating threat is detected by capturing a series of packets as the packets are communicated to nodes of the organizational network. The rapidly propagating threat can be detected without relying upon a known signature for the threat. Behavior of nodes when sending and receiving packets is examined for patterns typical of worm propagation.
信息查询