Virus monitor and methods of use thereof
First Claim
1. In a distributed network of interconnected computing devices, a network virus monitor, comprising:
- a virus sensor operable in a number of modes arranged to detect a computer virus in the network such that the bandwidth of the network is substantially unaffected in a first mode wherein when the virus sensor detects the computer virus the virus sensor switches to a second mode such that only those data packets infected by the computer virus are not returned to the network.
1 Assignment
0 Petitions
Accused Products
Abstract
A network level virus monitoring system capable of monitoring a flow of network traffic in any of a number of inspection modes depending upon the particular needs of a system administrator. The monitoring provides an early warning of a virus attack thereby facilitating quarantine procedures directed at containing a virus outbreak. By providing such an early warning, the network virus monitor reduces the number of computers ultimately affected by the virus attack resulting in a concomitant reduction in both the cost of repair to the system and the amount of downtime. In this way, the inventive network virus monitor provides a great improvement in system uptime and reduction in system losses.
-
Citations
23 Claims
-
1. In a distributed network of interconnected computing devices, a network virus monitor, comprising:
a virus sensor operable in a number of modes arranged to detect a computer virus in the network such that the bandwidth of the network is substantially unaffected in a first mode wherein when the virus sensor detects the computer virus the virus sensor switches to a second mode such that only those data packets infected by the computer virus are not returned to the network. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9)
-
10. A method of monitoring a distributed network of computing devices for a computer virus, comprising:
-
at a virus monitor coupled to the distributed network;
monitoring a flow of data packets in the network for the computer virus without substantially reducing the flow of data packets thereby preserving network bandwidth in a standby mode;
determining that at least one of the monitored data packets is infected with the computer virus; and
monitoring the flow of data packets such that the infected data packets are not returned to the flow of data packets in an inline mode based upon the determining. - View Dependent Claims (11, 12, 13, 14, 15, 16)
-
-
17. Computer program product for monitoring a distributed network of computing devices for a computer virus, comprising:
-
at a virus monitor coupled to the distributed network capable of executing computer code, computer code for monitoring a flow of data packets in the network for the computer virus without substantially reducing the flow of data packets thereby preserving network bandwidth in a standby mode;
computer code for determining that at least one of the monitored data packets is infected with the computer virus;
computer code for monitoring the flow of data packets such that the infected data packets are not returned to the flow of data packets in an inline mode based upon the determining; and
computer readable medium for storing the computer code. - View Dependent Claims (18, 19, 20, 21, 22, 23)
-
Specification