×

Containment of Unknown and Polymorphic Fast Spreading Worms

  • US 20080222729A1
  • Filed: 03/05/2008
  • Published: 09/11/2008
  • Est. Priority Date: 03/05/2007
  • Status: Abandoned Application
First Claim
Patent Images

1. A worm containment system, comprising:

  • a) a host computing machine having a host operating system, the host operating system configured to manage at least one host application;

    b) a virtual machine running under the control of a virtual machine monitor, the virtual machine having;

    i) a clone of the host operating system; and

    ii) a clone of the at least one host application;

    c) a worm detector configured to monitor the virtual machine traffic for signs of worm propagation;

    d) a splitter configured to duplicate packets intended for the host computing machine into;

    (1) diverted packets; and

    (2) buffered packets;

    e) a diverter configured to route the diverted packets to the virtual machine; and

    f) a buffer configured to;

    i) store the buffered packets; and

    ii) forward the buffered packets to the host operating system on indication from the worm detector that no worm propagation behavior was detected.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×