×

Apparatus and method for blocking zombie behavior process

  • US 20120174221A1
  • Filed: 08/09/2011
  • Published: 07/05/2012
  • Est. Priority Date: 01/04/2011
  • Status: Active Grant
First Claim
Patent Images

1. An apparatus for blocking a zombie behavior process performed in a computer connected to a network, the zombie behavior process being generated in the computer, and attacking external computers, comprising:

  • a security policy storage configured to store zombie-behavior-type-specific traffic characteristics and security policies;

    a traffic monitor configured to monitor traffic generated on the computer and detect abnormal traffic exceeding a predetermined reference value;

    a process and traffic analyzer configured to find an abnormal process causing the abnormal traffic, and detect a zombie behavior type associated with the abnormal process by analyzing the abnormal traffic on the basis of the zombie-behavior-type-specific traffic characteristics stored in the security policy storage; and

    a process handler configured to handle the process whose zombie behavior type has been detected according to a security policy defined for the detected zombie behavior type.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×