Device and method for worm detection, and computer product
First Claim
1. A computer program for detecting a worm by monitoring a communication of a predetermined network segment that is connected to a network and judging whether the communication is executed by a worm, causes a computer to perform:
- acquiring information related to a traffic and a communication address of a communication packet based on setting information; and
judging whether the communication is executed by the worm based on the information acquired and a predetermined judgment criteria.
1 Assignment
0 Petitions
Accused Products
Abstract
A communication-information acquisition section 240a acquires information related to a traffic and communication address of a communication packet based on setting information related to acquisition of information that is stored in setting-data. Worm detection section makes a judgment of whether a communication is executed by a worm based on information acquired by the communication-information acquisition section and information related to judgment criteria that is stored in the setting-data and which regulates whether the communication is executed by a worm.
-
Citations
20 Claims
-
1. A computer program for detecting a worm by monitoring a communication of a predetermined network segment that is connected to a network and judging whether the communication is executed by a worm, causes a computer to perform:
-
acquiring information related to a traffic and a communication address of a communication packet based on setting information; and
judging whether the communication is executed by the worm based on the information acquired and a predetermined judgment criteria. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11)
-
-
12. A computer-readable recording medium for storing a computer program for detecting a worm by monitoring a communication of a predetermined network segment that is connected to a network and judging whether the communication is executed by a worm, the computer program causing a computer to perform:
-
acquiring information related to a traffic and a communication address of a communication packet based on setting information; and
judging whether the communication is executed by the worm based on the information acquired and a predetermined judgment criteria.
-
-
13. A method for detecting a worm by monitoring a communication of a predetermined network segment that is connected to a network and judging whether the communication is executed by a worm, comprising:
-
acquiring information related to a traffic and a communication address of a communication packet based on setting information; and
judging whether the communication is executed by the worm based on the information acquired and a predetermined judgment criteria.
-
-
14. A device for detecting a worm by monitoring a communication of a predetermined network segment that is connected to a network and judging whether the communication is executed by a worm, comprising:
-
an acquiring unit that acquires information related to a traffic and a communication address of a communication packet based on setting information; and
a judging unit that judges whether the communication is executed by the worm based on the information acquired and a predetermined judgment criteria. - View Dependent Claims (15, 16, 17, 18, 19, 20)
-
Specification