Methods and systems for deceptively trapping electronic worms
First Claim
Patent Images
1. A method of trapping an electronic worm, the method comprising:
- detecting the electronic worm in an infected computer;
trapping the electronic worm; and
then communicating with the trapped electronic worm.
1 Assignment
0 Petitions
Accused Products
Abstract
Methods of trapping electronic worms are provided. Pursuant to these methods, an electronic worm may be “trapped” such that its ability to spread is reduced or eliminated, while at the same time the worm is deceived such that it does not realize it has been trapped. In this manner, the probability that the worm enacts countermeasures that are harmful to the data and/or equipment of the infected computing devices may be reduced. Corresponding systems of trapping electronic worms are also provided.
66 Citations
20 Claims
-
1. A method of trapping an electronic worm, the method comprising:
-
detecting the electronic worm in an infected computer;
trapping the electronic worm; and
thencommunicating with the trapped electronic worm. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11)
-
-
12. A method of blocking a communications from an electronic worm, the method comprising:
-
detecting a probe sent by the electronic worm;
blocking the probe from reaching an intended destination;
generating or formulating a response to the probe; and
forwarding the response to the probe to the electronic worm. - View Dependent Claims (13, 14, 15)
-
-
16. A system for trapping an electronic worm, comprising:
-
a probe detector that is configured to detect a probe from the electronic worm;
a database containing information on probe characteristics of a plurality of known types of worms;
a probe analyzer that is coupled to the probe detector and to the database;
a worm communications interceptor that is responsive to the probe analyzer and that is configured to intercept the probe to prevent it from reaching an intended destination; and
a deceptive-responder that is responsive to the worm communications interceptor. - View Dependent Claims (17, 18, 19, 20)
-
Specification