×

Apparatus method and medium for tracing the origin of network transmissions using n-gram distribution of data

  • US 20050265331A1
  • Filed: 11/12/2004
  • Published: 12/01/2005
  • Est. Priority Date: 11/12/2003
  • Status: Active Grant
First Claim
Patent Images

1. A method of tracing the location of an origin computer system that initially transmits a suspect data payload across a computer network to an end target computer system, the computer network having a plurality of computer systems, where each of the computer systems maintains connection records of transmitted data it receives, the transmitted data and connection records including a previous computer system address, a data payload, and a next computer system address, the method comprising the steps of:

  • (1) creating, at each of the computer systems, a connection record for each transmission received from another computer system through the computer network;

    (2) generating and storing a statistical distribution for the data payload in each connection record;

    (3) identifying the suspect data payload at the end target computer system and generating a statistical distribution of said suspect data payload;

    (4) setting the end target computer system as the suspect computer system;

    (5) comparing the suspect data payload statistical distribution to the data payload statistical distributions associated with connection records of the suspect computer system;

    (6) upon finding a data payload statistical distribution that is similar to the suspect data payload statistical distribution in said step (5), determining the previous computer system address associated with the similar data payload statistical distribution;

    (7) setting the computer system associated with the previous computer system address as the suspect computer system; and

    (8) repeating said steps (5)-(7) until the origin computer system is determined.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×