Anti-worm-measure parameter determining apparatus, number-of-nodes determining apparatus, number-of-nodes limiting system, and computer product
First Claim
1. A computer-readable recording medium that stores therein a computer program for determining parameters for controlling timing for an anti-worm-measure means to start blocking of a communication by a worm in a network, for preventing a spread of the worm, wherein the computer program causes a computer to execute:
- calculating infectivity of the worm based on number of nodes connected to the network; and
estimating an expected value of number of infected nodes at a time when the worm transmits a predetermined number of packets, based on the infectivity calculated at the calculating.
1 Assignment
0 Petitions
Accused Products
Abstract
An anti-worm-measure parameter determining apparatus determines parameters for controlling timing for an anti-worm-measure means to start blocking of a communication by a worm in a network, for preventing a spread of the worm. An infectivity calculating unit calculates infectivity of the worm based on number of nodes connected to the network. A number-of-infected-nodes estimating unit calculates an expected value of number of infected nodes at a time when the worm transmits a predetermined number of packets, based on the infectivity calculated by the infectivity calculating unit.
21 Citations
21 Claims
-
1. A computer-readable recording medium that stores therein a computer program for determining parameters for controlling timing for an anti-worm-measure means to start blocking of a communication by a worm in a network, for preventing a spread of the worm, wherein
the computer program causes a computer to execute: -
calculating infectivity of the worm based on number of nodes connected to the network; and
estimating an expected value of number of infected nodes at a time when the worm transmits a predetermined number of packets, based on the infectivity calculated at the calculating. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9)
-
-
10. An anti-worm-measure parameter determining apparatus that determines parameters for controlling timing for an anti-worm-measure means to start blocking of a communication by a worm in a network, for preventing a spread of the worm, the anti-worm-measure parameter determining apparatus comprising:
-
an infectivity calculating unit that calculates infectivity of the worm based on number of nodes connected to the network; and
a number-of-infected-nodes estimating unit that estimates an expected value of number of infected nodes at a time when the worm transmits a predetermined number of packets, based on the infectivity calculated by the infectivity calculating unit. - View Dependent Claims (11, 12, 13, 14, 15, 16, 17, 18)
-
-
19. A computer-readable recording medium that stores therein a computer program for determining number of nodes connectable to a network when an anti-worm-measure means is set to start blocking of a communication by a worm at predetermined timing, for preventing a spread of the worm, wherein
the computer program causes a computer to execute: -
calculating number of packets that can be leaked from packets transmitted from one infection source until the anti-worm-measure means completes the blocking of the communication by the worm;
estimating, based on infectivity of the worm calculated based on the number of nodes connected to the network and the number of packets calculated at the calculating, an expected value of number of nodes infected by the worm until the anti-worm-measure means completes the blocking of the communication by the worm; and
deriving, as an upper limit of number of nodes connectable to the network, number of nodes at a time when the expected value of the number of infected nodes estimated at the estimating becomes an finite maximum value when it is assumed that some number of packets have been transmitted by the worm.
-
-
20. A number-of-nodes determining apparatus that determines number of nodes connectable to a network when an anti-worm-measure means is set to start blocking of a communication by a worm at predetermined timing, for preventing a spread of the worm, the number-of-nodes limiting system comprising:
-
a limit-value-of-leaked-packets calculating unit that calculates number of packets that can be leaked from packets transmitted from one infection source until the anti-worm-measure means completes the blocking of the communication by the worm;
a number-of-infected-nodes estimating unit that estimates, based on infectivity of the worm calculated based on the number of nodes connected to the network and the number of packets calculated by the limit-number-of-leaked-packets calculating unit, an expected value of number of nodes infected by the worm until the anti-worm-measure means completes the blocking of the communication by the worm; and
a limit-number-of-nodes deriving unit that derives, as an upper limit of number of nodes connectable to the network, number of nodes at a time when the expected value of the number of infected nodes estimated by the number-of-infected-nodes estimating unit becomes an finite maximum value when it is assumed that some number of packets have been transmitted by the worm.
-
-
21. A number-of-nodes limiting system that limits number of nodes connectable to a network when an anti-worm-measure means is set to start blocking of a communication by a worm at predetermined timing, for preventing a spread of the worm, the number-of-nodes limiting system comprising:
-
a limit-value-of-leaked-packets calculating unit that calculates number of packets that can be leaked from packets transmitted from one infection source until the anti-worm-measure means completes the blocking of the communication by the worm;
a number-of-infected-nodes estimating unit that estimates, based on infectivity of the worm calculated based on the number of nodes connected to the network and the number of packets calculated by the limit-number-of-leaked-packets calculating unit, an expected value of number of nodes infected by the worm until the anti-worm-measure means completes the blocking of the communication by the worm;
a limit-number-of-nodes deriving unit that derives, as an upper limit of number of nodes connectable to the network, number of nodes at a time when the expected value of the number of infected nodes estimated by the number-of-infected-nodes estimating unit becomes an finite maximum value when it is assumed that some number of packets have been transmitted by the worm; and
a network-address allocating unit that allocates a network address to a node with the upper limit of number of nodes connectable to the network derived by the limit-number-of-nodes deriving unit as a limit.
-
Specification